PT-2026-71254 · Budibase · Budibase
CVE-2026-73303
·
Published
2026-07-24
·
Updated
2026-08-12
CVSS v3.1
8.2
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Budibase versions prior to 3.40.0
Description
An issue exists where the endpoint "/api/v2/email" accepts a client-controlled
accountId without binding it to the authenticated session, verifying only the currentEmail. An authenticated attacker with a victim's account identifier can initiate an email-change workflow, submit a verification code via the "/api/v2/email/verification" endpoint, change the victim's email to one controlled by the attacker, and subsequently perform a password reset to gain full account access.Recommendations
Update to version 3.40.0.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Budibase