High severity7.5NVD Advisory· Published Jul 8, 2026· Updated Jul 9, 2026
CVE-2026-10706
CVE-2026-10706
Description
In Adalo’s no-code app builder, (Versions 1 and 2) the attackers may extract full user records and correlate user behavior across multiple applications via dbId enumeration. The platform does not implement data minimization, privacy by design, or implement appropriate technical safeguards, allowing sensitive information to be exposed to unauthorized parties.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.