CVE-2026-10706
In Adalo’s no-code app builder, (Versions 1 and 2) the attackers may extract full user records and correlate user behavior across multiple a
CVSS
7.5
High
EPSS
0.3%
p22
KEV
—
Exploit Today
7
0-100
Published: Jul 8, 2026 · Last modified: Jul 9, 2026
0.1%EPSS · 30 days0.3%
2026-07-092026-07-21
In Adalo’s no-code app builder, (Versions 1 and 2) the attackers may extract full user records and correlate user behavior across multiple applications via dbId enumeration. The platform does not implement data minimization, privacy by design, or implement appropriate technical safeguards, allowing sensitive information to be exposed to unauthorized parties.
No related CVEs by CWE or product.