CVE-2026-40346 | nocobase up to 2.0.36 server-side request forgery (GHSA-mvvv-v22x-xqwp)
A vulnerability labeled as critical has been found in nocobase up to 2.0.36. This issue affects some unknown processing. Executing a manipulation can lead to server-side request forgery.
This vulnerability is handled as CVE-2026-40346. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.