PT-2026-71911 · Budibase · Budibase

·

CVE-2026-72856

·

Published

2026-08-13

·

Updated

2026-08-17

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Budibase versions prior to 3.40.0
Description An authorization and authentication bypass exists in the 'PUT /api/global/users/tenant/owner' (changeTenantOwnerEmail) endpoint. On self-hosted instances where SELF HOSTED or DISABLE ACCOUNT PORTAL are set, the cloudRestricted middleware is inactive. Consequently, the route is only protected by a general authentication check, allowing any authenticated user, including those with basic privileges, to reassign the tenant account-holder email to an address controlled by an attacker. This allows the attacker to utilize the public password-reset process to seize control of the administrative account and gain full administrative access.
Recommendations Update Budibase to version 3.40.0 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72856
GHSA-J82G-67X3-XCWH

Affected Products

Budibase