Unrated severityNVD Advisory· Published Jul 8, 2026· Updated Jul 9, 2026
Exposure of Sensitive Information to an Unauthorized attacker
CVE-2026-10706
Description
In Adalo’s no-code app builder, (Versions 1 and 2) the attackers may extract full user records and correlate user behavior across multiple applications via dbId enumeration. The platform does not implement data minimization, privacy by design, or implement appropriate technical safeguards, allowing sensitive information to be exposed to unauthorized parties.
Affected products
2- Range: 1, 2
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.