PT-2026-71914 · Budibase · Budibase

CVE-2026-73304

·

Published

2026-07-24

·

Updated

2026-08-13

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Budibase versions prior to 3.39.25
Description An issue exists where the endpoints 'GET /api/users/metadata' and 'GET /api/users/metadata/:id' return user objects processed by the packages/server/src/utilities/global.ts file without removing the oauth2.accessToken and oauth2.refreshToken variables. A user assigned the POWER role can retrieve identity-provider credentials of users authenticated via Single Sign-On (SSO), potentially using refresh tokens to maintain persistent access to connected services.
Recommendations Update to version 3.39.25.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73304
GHSA-FCRW-F7GG-6G9F

Affected Products

Budibase