CVE-2026-10706

7.5

Adalo · No-Code App Builder

Unauthenticated attackers can extract full user records and correlate behavior across applications via dbId enumeration in Adalo App Builder versions 1 and 2.

Executive summary

A sensitive information exposure vulnerability in the Adalo No-Code App Builder allows unauthenticated attackers to extract user records and correlate behavior.

Vulnerability

This vulnerability is an exposure of sensitive information to an unauthorized actor via CWE-200, allowing unauthenticated attackers to perform dbId enumeration over the network.

Business impact

A successful exploit allows malicious actors to harvest complete user records and track user behavior across multiple built applications, leading to severe privacy violations and potential regulatory non-compliance. With a CVSS score of 7.5, this high-severity flaw exposes critical data assets without requiring any prior authentication or user interaction.

Remediation

Immediate Action: Update the Adalo No-Code App Builder to the latest patched version as soon as released by the vendor, or apply vendor-supplied platform updates.

Proactive Monitoring: Monitor API endpoints and access logs for unusual patterns of sequential dbId requests or rapid enumeration attempts.

Compensating Controls: Implement strict rate limiting at the network edge or Web Application Firewall layer to detect and block enumeration traffic targeting user identification parameters.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations utilizing Adalo App Builder versions 1 and 2 must review their exposure and coordinate with the vendor to secure database identifiers. Administrators should apply available updates immediately and review application access logs to protect sensitive user data from unauthorized harvesting.

Sources