PT-2026-99359 · Budibase · Budibase

·

CVE-2026-100688

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Budibase server versions prior to 3.45.0
Description An information disclosure issue exists where authenticated users can access application metadata and source code belonging to another tenant. By providing a victim tenant's appId to the 'GET /api/applications/:appId/appPackage' endpoint, an attacker can retrieve sensitive details such as navigation structure, role names, internal screen URLs, JavaScript snippets, and user identifiers due to a lack of authorization checks.
Recommendations Update Budibase server to version 3.45.0 or later. Restrict access to the 'GET /api/applications/:appId/appPackage' endpoint to minimize the risk of exploitation.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100688
GHSA-4946-QF2M-WRH5

Affected Products

Budibase