PT-2026-83094 · Budibase · Budibase
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
Budibase versions prior to 3.41.3
Description
An authorization flaw exists in the 'POST /api/resources/duplicate' endpoint. Authenticated builders can inject tables, automations, queries, and screens into any application by specifying an arbitrary destination workspace ID in the request body, even without a role in the target workspace. This allows attackers to trigger injected automations using outgoing webhooks to exfiltrate data from the victim applications.
Recommendations
Update Budibase to version 3.41.3 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Budibase