External risk intelligence

NocoBase SQL Injection Vulnerability Allows Database Access

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-88402

NocoBase is a low-code development platform typically deployed as a web application. Such platforms are commonly exposed to the internet to provide access to database interfaces, APIs, and administrative dashboards, making them highly probable to have a public-facing network presence in standard deployment scenarios.

SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in nocobase, a low-code development platform, related to how it handles database queries. This issue, if exploited, could allow unauthorized access to sensitive information stored within the application's database. While the primary concern is to confirm if nocobase is in use within our environment, understanding the potential for data exposure is important.

  • Database query flaw allows sensitive data access.
  • Confirm use of nocobase; assess potential data exposure.
  • Understand risk; verify relevance and system exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending specially crafted SQL statements to the checkSQL function. This function is exposed via the web interface, and since no authentication is required, an unauthenticated attacker can trigger the vulnerability, leading to the disclosure of sensitive database information.

  • No authentication needed for access.
  • Triggered by injecting SQL into the checkSQL function.
  • Risk of accessing sensitive database information.

Live Threat

Current exploitation, exposure, and threat context

A SQL injection vulnerability in the checkSQL function could allow attackers to access sensitive database information by injecting crafted SQL statements. This could occur when the application processes user-supplied input without proper sanitization, potentially exposing the contents of the application's database.

  • Database information.
  • Via crafted SQL statements.
  • Unauthorized access to sensitive data.

Operational Fix

Recommended remediation, mitigation, and detection steps

This SQL injection vulnerability impacts NocoBase deployments. Responsibility likely falls to application owners and platform teams managing the NocoBase instances, with support from network and security teams for exposure assessment. The immediate priority is to inventory all NocoBase instances, determine their internet reachability and business criticality, identify the accountable owner for each instance, and then assess the risk to plan remediation actions.

  • Application owners should verify NocoBase instances.
  • Confirm external reachability and business criticality.
  • Plan remediation based on identified risks.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is NocoBase?

NocoBase is a low-code development platform used to build custom business applications and internal tools. It provides a web-based interface that allows users to design database structures, create custom workflows, and manage data without extensive manual coding. Because it often serves as a central hub for organizational data and administrative functions, it is typically deployed as a web application that interfaces directly with an underlying database.

What does CWE-89 mean for CVE-2026-88402?

CVE-2026-88402 involves a SQL injection weakness, classified as CWE-89. This means the application fails to properly sanitize user input before including it in a database query. In this case, an attacker can input specially crafted SQL code into the checkSQL function. Because the application processes this malicious input as a valid command, it inadvertently grants the attacker the ability to view, modify, or interact with the database contents that the platform is supposed to protect.

How is the CVE-2026-88402 vulnerability triggered?

The flaw is triggered by sending a malformed SQL statement to the checkSQL function via the web interface. A key aspect of this vulnerability is that it does not require the attacker to have a user account or perform any authentication steps. It is important to note that actions performed through legitimate, non-malicious use of the interface do not trigger the vulnerability; the issue is specifically the application's failure to distinguish between valid data and malicious SQL commands.

Why should I care about this SQL injection if my NocoBase instance is internal?

Halo Surface Signal notes that because NocoBase is designed for web access, many instances are configured to be internet-facing to support remote users or external integrations. If your instance is exposed to the internet, it is reachable by unauthenticated attackers globally. Even if your instance is currently internal, evaluating its reachability is critical, as any misconfiguration that exposes the platform to a wider network increases the risk of unauthorized database access.

How do I respond to the CVE-2026-88402 threat?

Your first step is to perform an inventory to locate all active NocoBase deployments within your environment. Once identified, determine the network reachability of each instance and assess the sensitivity of the data stored in the associated databases. Engage with the specific owners of these instances to evaluate their business criticality and coordinate a plan to apply necessary security updates or implement compensating controls to mitigate the risk of unauthorized database interaction.

References