A vulnerability has been found in Baserow up to 2.3.2 and classified as problematic. Affected by this issue is the function
BaserowImpersonateAuthTokenSerializer of the file backend/src/baserow/api/admin/users/serializers.py of the component Inactive Non-Staff User Handler. Performing a manipulation results in improper authorization.
This vulnerability is known as CVE-2026-18817. Remote exploitation of the attack is possible. No exploit is available.
The presence of this vulnerability remains uncertain at this time.
The affected component should be upgraded.
The project maintainer explains: “While the problem exists, I’m not really sure if it’s a vulnerability. (….) Even though the back gives a token for a deactivate user, none of the endpoints actually work. That said, we will fix it, but so far it seems more like a bug instead of a vulnerability.”