PT-2026-99355 · Budibase · Budibase
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Budibase versions 3.41.0 through 3.44.9
Description
An authentication bypass exists in the OIDC/SSO login path of @budibase/server. Within the
sso.authenticate function, the server fails to validate an invite code or perform an email verified check when looking up pending user invites by the IdP-asserted email address if no existing user matches the SSO subject. An attacker capable of registering at a trusted Identity Provider (IdP) and asserting a victim's invited email address can claim the pending invite. This allows the attacker to inherit all granted privileges, such as builder and admin.global, leading to the takeover of the invited principal and full tenant compromise, including access to all applications, datasources, production credentials, and automations.Recommendations
Update Budibase to version 3.45.0 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Budibase