PT-2026-83092 · Budibase · Budibase

·

CVE-2026-82240

·

Published

2026-08-28

·

Updated

2026-08-28

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Budibase versions prior to 3.41.3
Description Insufficient validation of app-scoped builder role assignments occurs in the public user create and update endpoints. An authenticated app-scoped builder can escalate privileges by submitting crafted requests to the user update API using the builder.apps field, allowing them to grant themselves unauthorized builder access to other applications within the same tenant.
Recommendations Update to version 3.41.3 or later.

Exploit

Fix

LPE

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82240
GHSA-468G-55QJ-V8RR

Affected Products

Budibase