PT-2026-83097 · Budibase · Budibase

·

CVE-2026-82245

·

Published

2026-08-28

·

Updated

2026-08-28

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Budibase versions prior to 3.41.3
Description Insufficient role-based authorization on license management endpoints allows any authenticated user to delete license keys or manipulate offline tokens. Users with basic privileges can access the /api/global/license/* endpoints to disable premium features and downgrade deployments for all users.
Recommendations Update to version 3.41.3 or later. Restrict access to the /api/global/license/* endpoints as a temporary mitigation measure.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82245
GHSA-4WR8-5C3P-RJCR

Affected Products

Budibase