PT-2026-71913 · Budibase · Budibase

CVE-2026-73302

·

Published

2026-07-24

·

Updated

2026-08-13

CVSS v4.0

9.0

Critical

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Budibase versions prior to 3.39.30
Description The OIDC flow in packages/backend-core/src/middleware/passport/sso/oidc.ts resolves an email without requiring getEmailVerified or email verified. Subsequently, packages/backend-core/src/middleware/passport/sso/sso.ts uses the users.getGlobalUserByEmail() function as a fallback account-linking key. This allows an attacker to authenticate via a configured identity provider that asserts an unverified email belonging to a victim, enabling the attacker to merge a new provider identity into the victim's account and inherit their roles.
Recommendations Update to version 3.39.30.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73302
GHSA-HP6V-6JW7-GV2F

Affected Products

Budibase