PT-2026-71906 · Budibase · Budibase

·

CVE-2026-72849

·

Published

2026-07-24

·

Updated

2026-08-13

CVSS v4.0

8.7

High

VectorAV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Budibase versions prior to 3.40.0
Description A cross-site request forgery (CSRF) issue exists in the 'chat-link handoff' endpoint. This allows an attacker to bind an external chat identity to a victim's account by crafting a phishing page that automatically submits a POST request containing a leaked confirmation token. Successful exploitation enables the attacker to impersonate the victim within agent operations and inherit their permissions.
Recommendations Update to version 3.40.0 or later.

Exploit

Fix

Improper Authorization

Insufficient Verification of Data Authenticity

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72849
GHSA-PVCR-8MVP-W8QR

Affected Products

Budibase