CVE-2026-10708: CWE-522 Insufficiently Protected Credentials in Adalo No-Code App Builder App Builder
This vulnerability enables large‑scale data harvesting without requiring app‑specific secrets. A single request to a minimal leaderboard component may return user records containing emails, UUIDs, and custom fields. The combination of wildcard CORS behavior, long‑lived twenty‑day JWTs, and the absence of token revocation allows attackers to gather sensitive personal information from any Adalo application.
AI Analysis
Technical Summary
This vulnerability (CVE-2026-10708) in the Adalo No-Code App Builder involves insufficient protection of credentials (CWE-522), improper validation of tokens (CWE-346), and inadequate expiration handling (CWE-613). The combination of permissive CORS policies, long-lived JWTs without revocation, and a minimal leaderboard component that returns sensitive user data allows unauthorized large-scale data harvesting. Attackers can exploit this by sending a single request to the vulnerable component to retrieve user emails, UUIDs, and custom fields from any app built with Adalo.
Potential Impact
The vulnerability enables unauthorized disclosure of sensitive personal information such as user emails, UUIDs, and custom fields from any application built with Adalo. This can lead to privacy violations and potential misuse of harvested data. There is no indication of impact on data integrity or availability. No known exploits are reported in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory at https://kb.cert.org/vuls/id/849433 for current remediation guidance. Until an official fix is available, developers should consider restricting CORS policies, reducing JWT lifespan, and implementing token revocation mechanisms to mitigate risk. Monitor vendor communications for updates on patches or official mitigations.
CVE-2026-10708: CWE-522 Insufficiently Protected Credentials in Adalo No-Code App Builder App Builder
Description
This vulnerability enables large‑scale data harvesting without requiring app‑specific secrets. A single request to a minimal leaderboard component may return user records containing emails, UUIDs, and custom fields. The combination of wildcard CORS behavior, long‑lived twenty‑day JWTs, and the absence of token revocation allows attackers to gather sensitive personal information from any Adalo application.
CVSS v3.1
Score 7.5high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-10708) in the Adalo No-Code App Builder involves insufficient protection of credentials (CWE-522), improper validation of tokens (CWE-346), and inadequate expiration handling (CWE-613). The combination of permissive CORS policies, long-lived JWTs without revocation, and a minimal leaderboard component that returns sensitive user data allows unauthorized large-scale data harvesting. Attackers can exploit this by sending a single request to the vulnerable component to retrieve user emails, UUIDs, and custom fields from any app built with Adalo.
Potential Impact
The vulnerability enables unauthorized disclosure of sensitive personal information such as user emails, UUIDs, and custom fields from any application built with Adalo. This can lead to privacy violations and potential misuse of harvested data. There is no indication of impact on data integrity or availability. No known exploits are reported in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory at https://kb.cert.org/vuls/id/849433 for current remediation guidance. Until an official fix is available, developers should consider restricting CORS policies, reducing JWT lifespan, and implementing token revocation mechanisms to mitigate risk. Monitor vendor communications for updates on patches or official mitigations.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- certcc
- Date Reserved
- 2026-06-02T17:59:57.666Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://kb.cert.org/vuls/id/849433","vendor":"CERT"}]
Threat ID: 6a4e65c0c9d9e3dbe34c9ab6
Added to database: 07/08/2026, 14:59:12 UTC
Last enriched: 07/16/2026, 10:01:37 UTC
Last updated: 08/22/2026, 10:52:07 UTC
Views: 87
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.