CVE-2026-10706: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in Adalo No-Code App Builder App Builder
In Adalo’s no-code app builder, (Versions 1 and 2) the attackers may extract full user records and correlate user behavior across multiple applications via dbId enumeration. The platform does not implement data minimization, privacy by design, or implement appropriate technical safeguards, allowing sensitive information to be exposed to unauthorized parties.
AI Analysis
Technical Summary
This vulnerability in Adalo No-Code App Builder enables unauthorized actors to access sensitive user information by enumerating database IDs (dbId). Due to insufficient implementation of data minimization and privacy principles, attackers can extract complete user records and correlate user behavior across multiple applications built on the platform. The CVSS score of 7.5 indicates a high-severity issue with network attack vector, low attack complexity, no privileges or user interaction required, and impacts confidentiality without affecting integrity or availability. No patch or official remediation level has been provided, and no known exploits are reported in the wild as of the publication date.
Potential Impact
Sensitive user information can be exposed to unauthorized parties, compromising user privacy and potentially enabling further privacy violations or targeted attacks. The confidentiality of user data is fully impacted, while integrity and availability remain unaffected.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory at https://kb.cert.org/vuls/id/849433 for current remediation guidance. Until an official fix is available, users should consider limiting exposure of sensitive data and monitoring for unusual access patterns related to dbId enumeration.
CVE-2026-10706: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in Adalo No-Code App Builder App Builder
Description
In Adalo’s no-code app builder, (Versions 1 and 2) the attackers may extract full user records and correlate user behavior across multiple applications via dbId enumeration. The platform does not implement data minimization, privacy by design, or implement appropriate technical safeguards, allowing sensitive information to be exposed to unauthorized parties.
CVSS v3.1
Score 7.5high
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in Adalo No-Code App Builder enables unauthorized actors to access sensitive user information by enumerating database IDs (dbId). Due to insufficient implementation of data minimization and privacy principles, attackers can extract complete user records and correlate user behavior across multiple applications built on the platform. The CVSS score of 7.5 indicates a high-severity issue with network attack vector, low attack complexity, no privileges or user interaction required, and impacts confidentiality without affecting integrity or availability. No patch or official remediation level has been provided, and no known exploits are reported in the wild as of the publication date.
Potential Impact
Sensitive user information can be exposed to unauthorized parties, compromising user privacy and potentially enabling further privacy violations or targeted attacks. The confidentiality of user data is fully impacted, while integrity and availability remain unaffected.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory at https://kb.cert.org/vuls/id/849433 for current remediation guidance. Until an official fix is available, users should consider limiting exposure of sensitive data and monitoring for unusual access patterns related to dbId enumeration.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- certcc
- Date Reserved
- 2026-06-02T17:46:45.590Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://kb.cert.org/vuls/id/849433","vendor":"CERT"}]
Threat ID: 6a4e65c0c9d9e3dbe34c9ab3
Added to database: 07/08/2026, 14:59:12 UTC
Last enriched: 07/16/2026, 10:01:30 UTC
Last updated: 08/22/2026, 10:52:07 UTC
Views: 72
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.