PT-2026-71911 · Budibase · Budibase
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Budibase versions prior to 3.40.0
Description
An authorization and authentication bypass exists in the 'PUT /api/global/users/tenant/owner' (changeTenantOwnerEmail) endpoint. On self-hosted instances where
SELF HOSTED or DISABLE ACCOUNT PORTAL are set, the cloudRestricted middleware is inactive. Consequently, the route is only protected by a general authentication check, allowing any authenticated user, including those with basic privileges, to reassign the tenant account-holder email to an address controlled by an attacker. This allows the attacker to utilize the public password-reset process to seize control of the administrative account and gain full administrative access.Recommendations
Update Budibase to version 3.40.0 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Budibase