Adalo No-Code Application Platform Database API Cross-App User Data Exposure Vulnerability

Vulnerability

A vulnerability in the Adalo database API allows authenticated users to access complete user records from any Adalo application, bypassing application-specific authorization controls. This issue arises from the API's failure to enforce ownership-aware, server-side authorization checks, combined with a permissive CORS policy and the exposure of long-lived JWT tokens. As a result, attackers can automate the extraction of sensitive personal information, including emails and custom fields, from over one million Adalo applications.

Impact

Exploitation of this vulnerability leads to unauthorized access and extraction of full user records, including sensitive personal information, from any Adalo application.

Remediation

Adalo has acknowledged this access control weakness but has not yet released a patch. In the meantime, users should avoid storing sensitive information in Adalo collections and remain vigilant for phishing and identity theft risks.

Added: Jul 8, 2026, 4:49 PM
Updated: Jul 8, 2026, 4:49 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
9.6
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.