A vulnerability, which was classified as critical, was found in Baserow up to 2.3.2. Affected by this vulnerability is the function verify of the file backend/src/baserow/api/two_factor_auth/views.py of the component 2FA Verify Endpoint. Such manipulation leads to improper authentication.

This vulnerability is traded as CVE-2026-18816. The attack may be launched remotely. There is no exploit available.

You should upgrade the affected component.

The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.