PT-2026-83094 · Budibase · Budibase

·

CVE-2026-82242

·

Published

2026-08-28

·

Updated

2026-08-28

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Budibase versions prior to 3.41.3
Description An authorization flaw exists in the 'POST /api/resources/duplicate' endpoint. Authenticated builders can inject tables, automations, queries, and screens into any application by specifying an arbitrary destination workspace ID in the request body, even without a role in the target workspace. This allows attackers to trigger injected automations using outgoing webhooks to exfiltrate data from the victim applications.
Recommendations Update Budibase to version 3.41.3 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82242
GHSA-XQPQ-288M-R5Q7

Affected Products

Budibase