← Terug naar overzicht

Budibase versions before 3.41.3 contain a critical authorization bypass vulnerability in the POST /api/datasources/query endpoint. The flaw allows low-privilege BASIC role users to bypass per-table role restrictions entirely. Attackers can read, create, update, or delete rows in any table regardless of configured permissions. The attack vector involves submitting crafted query requests with target table identifiers. This effectively nullifies table-level access controls within the Budibase platform. The vulnerability poses significant risk to data confidentiality and integrity for any Budibase deployment. Organizations using Budibase should upgrade to version 3.41.3 or later immediately. No special conditions beyond having a BASIC role account appear to be required for exploitation.

Affected products

  • Budibase

Related CVE's

  • CVE-2026-82239

Categories

  • Database & Storage
  • Enterprise Applications
  • Identity & Access
  • Web Technologies