Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Moratoantoine

#33149of 57,338
8.6Total CVSS
Vulnerabilities · 1
PT-2026-99357
8.6
2026-09-26
Budibase · Budibase · CVE-2026-100686
**Name of the Vulnerable Software and Affected Versions** Budibase versions prior to 3.45.0 **Description** Insufficient per-app authorization validation in the 'POST /api/global/groups/:groupId/apps' endpoint allows users with builder privileges to assign application roles across workspace boundaries. An attacker with builder access to a single workspace can modify user group role mappings to grant themselves administrative roles in other workspaces. **Recommendations** Update to version 3.45.0 or later.