PT-2026-71915 · Budibase · Budibase

CVE-2026-73305

·

Published

2026-07-24

·

Updated

2026-08-18

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Budibase versions prior to 3.39.24
Description An issue exists where the endpoint "/api/public/v1/roles/assign" calls the validateGlobalRoleUpdate() function without verifying the appBuilder.appId or role.appId variables. This allows an app-scoped builder to scope a request to an application they control and grant themselves builder access or an arbitrary role in a different application. This could lead to the exposure of application data, datasource configurations, and automations.
Recommendations Update to version 3.39.24.

Exploit

Fix

Incorrect Authorization

Missing Authorization

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73305
GHSA-J9FC-W3MR-X6MV

Affected Products

Budibase