CVE-2026-46548: NocoDB Webhook SSRF Vulnerability – Patch & Detection Guide
NocoDB, a database-as-spreadsheet platform, contains a server-side request forgery (SSRF) vulnerability in its webhook notification system. An authenticated user with permissions to create webhooks can craft malicious requests to the Slack, Discord, Mattermost, or Teams webhook plugins that bypass intended network protections, allowing them to reach internal hosts that should be off-limits. The flaw stems from improper configuration of HTTP agent settings in four webhook integrations. This issue is resolved in version 2026.04.1 and later.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 4.3 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Weaknesses (CWE)
- CWE-918
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-23 / 2026-06-25
NVD description (verbatim)
NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the request-filtering-agent SSRF protection was non-functional in the four notification webhook plugins (Slack, Discord, Mattermost, Teams) because httpAgent / httpsAgent were passed as part of the request body rather than the axios config. An authenticated user with hook-creation permission could direct outbound POST requests to arbitrary internal hosts. This vulnerability is fixed in 2026.04.1.
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
NocoDB versions prior to 2026.04.1 fail to enforce SSRF protections in the notification webhook plugins for Slack, Discord, Mattermost, and Teams. The vulnerability arises because httpAgent and httpsAgent parameters—which control proxy and certificate validation behavior—are incorrectly passed within the request body instead of the axios HTTP client configuration object. An authenticated attacker can manipulate these parameters to direct outbound POST requests to arbitrary internal IP addresses or hostnames, circumventing network segmentation policies. The attack requires valid credentials and hook-creation permissions within the NocoDB instance.
Business impact
While the CVSS score is moderate (4.3), the practical impact depends on deployment context. In environments where NocoDB instances have network access to sensitive internal services (databases, APIs, administrative interfaces), a compromised or malicious user with webhook creation privileges could reconnaissance or interact with those backends without direct access. In cloud or shared hosting scenarios, this could enable lateral movement. Organizations using NocoDB in air-gapped or heavily segmented networks face lower risk. The requirement for authentication limits exposure to insider threats or credential compromise scenarios.
Affected systems
NocoDB installations prior to version 2026.04.1 are affected. The vulnerability is specific to the four notification webhook plugins (Slack, Discord, Mattermost, Teams) and requires the attacker to hold webhook creation permissions within a NocoDB instance. Community deployments, self-hosted instances, and managed NocoDB services running unpatched versions are all susceptible. No vendor advisory indicates widespread pre-release exploitation.
Exploitability
Exploitation requires valid NocoDB user credentials and explicit permission to create webhooks—typically a privilege restricted to workspace administrators or designated integrators. The attack is not remotely exploitable without authentication. No public exploit code or weaponized proof-of-concept has been disclosed as of the advisory date. An attacker would need to craft a webhook request with malformed agent parameters and have detailed knowledge of target internal infrastructure to succeed. The barrier to exploitation is moderate: authentication plus privilege requirements, but straightforward once those preconditions are met.
Remediation
Upgrade NocoDB to version 2026.04.1 or later, which corrects the HTTP agent configuration to properly pass these settings through the axios client options rather than the request body. For organizations unable to patch immediately, restrict webhook creation permissions to fully trusted administrators and implement egress firewall rules to prevent NocoDB instances from reaching sensitive internal services. Monitor webhook creation and modification events for suspicious activity.
Patch guidance
Apply NocoDB version 2026.04.1 or newer through your standard deployment mechanism (Docker image update, npm package upgrade, or managed service upgrade if applicable). Verify the patch is in place by checking the running version in the NocoDB admin interface or application logs. No special migration or configuration changes are required post-upgrade. Test webhook functionality with Slack, Discord, Mattermost, and Teams integrations after patching to confirm normal operations are restored.
Detection guidance
Monitor NocoDB webhook logs and activity for unusual webhook creation or modification by non-administrative users. Flag webhook requests that target internal IP ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) or localhost. Examine HTTP access logs on internal services for unexpected POST requests originating from NocoDB instances. Alert on webhook plugins that fail with suspicious timing or frequency. Implement network-layer detection by alerting on outbound connections from NocoDB to internal-only network segments.
Why prioritize this
Although CVSS scoring is moderate, prioritize patching in the following order: (1) NocoDB instances with administrative users or high-privilege accounts, particularly if those users are contractors or temporary staff; (2) instances with network visibility to production databases, APIs, or administrative consoles; (3) environments where webhook creation is broadly permitted. Lower priority for air-gapped deployments, single-admin environments with strong access controls, or instances without internal network reach.
Risk score, explained
The CVSS v3.1 score of 4.3 (MEDIUM) reflects a network-accessible attack requiring authentication and low privileges, resulting in confidentiality impact but no integrity or availability loss. The score appropriately captures that this is an internal reconnaissance vector rather than a critical system compromise. However, organizational risk is context-dependent: in zero-trust or highly segmented networks, actual risk is lower; in flat networks with permissive webhook policies, risk is elevated.
Frequently asked questions
Can this vulnerability be exploited without a valid NocoDB user account?
No. Exploitation requires valid authentication credentials and explicit webhook creation permissions. External attackers without credentials cannot exploit this flaw. Insider threats or compromised accounts are the primary attack vector.
Does the patch require downtime or data migration?
No. Version 2026.04.1 is a straightforward upgrade with no breaking changes, schema migrations, or extended downtime required. Existing webhooks will continue to function normally after patching.
How can I verify my NocoDB instance is vulnerable?
Check your running version in NocoDB's admin interface or logs. If it reports a version earlier than 2026.04.1, you are vulnerable. Verify the four webhook plugins (Slack, Discord, Mattermost, Teams) are installed and accessible.
If we don't use the webhook plugins mentioned, are we still vulnerable?
The vulnerability is specific to the Slack, Discord, Mattermost, and Teams webhook plugins. If these plugins are not installed or enabled, your instance is not affected by this particular issue, though you should verify your NocoDB version for other potential vulnerabilities.
This analysis is provided for informational purposes and based on publicly available CVE data and vendor advisories as of the publication date. Security assessments are context-dependent; actual organizational risk varies based on deployment architecture, access controls, and network segmentation. Organizations should independently validate patch applicability and test in non-production environments before widespread deployment. SEC.co makes no warranty regarding the completeness or accuracy of this analysis beyond the core CVE record. For authoritative guidance, consult the NocoDB project security advisories and your internal security team. Source: NVD (public-domain), retrieved 2026-07-29. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2025-58175MEDIUMGeoServer SSRF Vulnerability in Proxy Configuration
- CVE-2026-10052MEDIUMQuay SSRF in LDAP/SMTP Validation—Internal Network Reconnaissance Risk
- CVE-2026-10177MEDIUMSSRF in Aider-AI Aider 0.86.3 AWS Metadata Endpoint
- CVE-2026-10239MEDIUMJeecgBoot Server-Side Request Forgery (SSRF) in Word Editing Module
- CVE-2026-10240MEDIUMJeecgBoot SSRF Vulnerability in /airag/airagModel/test Endpoint
- CVE-2026-10241MEDIUMJimuReport SSRF in File Download Function – Patch to 3.9.2
- CVE-2026-10274MEDIUMServer-Side Request Forgery in aem-mcp-server
- CVE-2026-10276MEDIUMJenkins-server-mcp SSRF Vulnerability (0.1.0)