← Back to overview

Budibase versions before 3.41.3 contain a privilege escalation vulnerability in the public user create and update endpoints. The flaw stems from a failure to validate app-scoped builder role assignments, allowing an authenticated app-scoped builder to grant themselves or others builder access to unrelated applications within the same tenant. Attackers can exploit this by submitting crafted requests to the user update API using the builder.apps field. This enables unauthorized builder access to other applications, effectively bypassing intended access controls. The vulnerability is classified as high severity given the potential for lateral privilege escalation across applications in a multi-tenant environment. A fix has been released in Budibase version 3.41.3. Security advisories have been published by both GitHub and VulnCheck.

Affected products

  • Budibase

Related CVE's

  • CVE-2026-82240

Categories

  • Enterprise Applications
  • Identity & Access
  • Web Technologies