Adalo No-Code App Builder User Data Exposure Vulnerability

Vulnerability

A vulnerability in Adalo's no-code app builder, affecting versions 1 and 2, allows authenticated users to extract full user records from the database API of any application on the platform. This issue arises from a lack of proper authorization checks, enabling the retrieval of complete user data, including unrequested fields, across more than one million applications. The vulnerability is exacerbated by a permissive CORS policy and the plaintext storage of text files, with evidence suggesting that deleted records may still be accessible.

Impact

The vulnerability leads to unauthorized access and extraction of sensitive user information, including emails, UUIDs, and custom fields, from any Adalo application. This data can be harvested in large volumes using exposed, long-lived JWT tokens, without the need for app-specific credentials.

Remediation

Adalo has acknowledged this vulnerability but has not yet released a patch. Users are advised to avoid storing sensitive information in Adalo collections until a fix is available and to monitor their accounts for suspicious activity.

Added: Jul 8, 2026, 5:05 PM
Updated: Jul 8, 2026, 5:05 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
0.0
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.