PT-2026-67878 · Baserow · Baserow

·

CVE-2026-18817

·

Published

2026-08-04

·

Updated

2026-08-04

CVSS v3.1

2.2

Low

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Baserow versions prior to 2.3.3
Description An issue in the Inactive Non-Staff User Handler component allows for improper authorization through the manipulation of the BaserowImpersonateAuthTokenSerializer() function located in the backend/src/baserow/api/admin/users/serializers.py file. This flaw enables remote exploitation, although the attack complexity is high and exploitation is considered difficult. The project maintainer has noted that while a token may be issued for a deactivated user, the endpoints may not actually function, suggesting the issue may behave more like a bug than a security flaw.
Recommendations Update to version 2.3.3.

Exploit

Fix

Incorrect Privilege Assignment

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18817

Affected Products

Baserow