What is CVE-2026-18816?
An improper authentication vulnerability was identified in Baserow versions up to 2.3.2, affecting the `verify` function in the `backend/src/baserow/api/two_factor_auth/views.py` file within the 2FA Verify Endpoint. This flaw could allow remote attackers to bypass two-factor authentication. Users should apply the patch immediately.
Azərbaycanca: Baserow 2.3.2-ə qədər versiyalarda 2FA Verify Endpoint-də improper authentication zəifliyi aşkarlanıb. Bu, `backend/src/baserow/api/two_factor_auth/views.py` faylındakı `verify` funksiyasına təsir edir və uzaqdan autentifikasiya yan keçidinə səbəb ola bilər. İstifadəçilərə dərhal yamaq tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287; shared vendor: Baserow
FAQ2
Which versions of Baserow are affected by this authentication vulnerability?
The vulnerability affects Baserow versions up to 2.3.2.
Which file contains the flaw in the Baserow 2FA Verify Endpoint?
The flaw is located in the `verify` function within the `backend/src/baserow/api/two_factor_auth/views.py` file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.