PT-2026-99355 · Budibase · Budibase

·

CVE-2026-100684

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Budibase versions 3.41.0 through 3.44.9
Description An authentication bypass exists in the OIDC/SSO login path of @budibase/server. Within the sso.authenticate function, the server fails to validate an invite code or perform an email verified check when looking up pending user invites by the IdP-asserted email address if no existing user matches the SSO subject. An attacker capable of registering at a trusted Identity Provider (IdP) and asserting a victim's invited email address can claim the pending invite. This allows the attacker to inherit all granted privileges, such as builder and admin.global, leading to the takeover of the invited principal and full tenant compromise, including access to all applications, datasources, production credentials, and automations.
Recommendations Update Budibase to version 3.45.0 or later.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100684
GHSA-35CH-57G2-3G98

Affected Products

Budibase