CVE-2026-34156
NocoBase, an AI‑powered no‑code platform, had a flaw that let authenticated users run arbitrary code as the system owner. The bug was fixed in version 2.0.28. Users of earlier releases should update immediately.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
NocoBase platform, any installation running a version older than 2.0.28, typically developers and administrators building business applications.
Real-world impact
An attacker who can log in to the platform can escape a sandboxed JavaScript environment and execute any code on the host machine with root privileges, potentially taking full control of the server.
Why this severity
The CVSS score of 9.9 reflects that the vulnerability allows remote code execution with low effort, requires only authenticated access, and gives the attacker full control of the system, making it a critical risk.
What to do about it
- 01Upgrade NocoBase to version 2.0.28 or later.
- 02Restart the NocoBase service to apply the update.
NVD-referenced vendor advisory
Timeline
- Mar 31, 2026 · Mar 31, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
- Jul 26, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- github.com/nocobase/nocobase/pull/8967issue trackingpatch
- github.com/nocobase/nocobase/releases/…productrelease notes
- github.com/nocobase/nocobase/security/…exploitmitigationvendor advisory