CVE-2026-10708
Adalo No-Code App Builder App Builder 취약점
This vulnerability enables large‑scale data harvesting without requiring app‑specific secrets. A single request to a minimal leaderboard component may return user records containing emails, UUIDs, and custom fields. The combination of wildcard CORS behavior, long‑lived twenty‑day JWTs, and the absence of token revocation allows attackers to gather sensitive personal information from any Adalo application.
- 대응 우선순위
- 점검
- CVSS
- 7.5
- EPSS
- 0.20% 백분위 9.61% · 2026.08.03 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.07.09