PT-2026-56454 · Adalo · Adalo
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Adalo versions 1 through 2
Description
Attackers can extract complete user records and correlate user behavior across multiple applications through the enumeration of the
dbId variable. This occurs because the platform lacks data minimization, privacy by design, and necessary technical safeguards, which leads to the exposure of sensitive information to unauthorized parties.Recommendations
Update Adalo versions 1 through 2 to a version that implements appropriate technical safeguards and data minimization to prevent
dbId enumeration.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Adalo