← Terug naar overzicht

Budibase versions before 3.41.3 contain a vulnerability in the public user create and update endpoints that fails to validate app-scoped builder role assignments. An authenticated app-scoped builder can exploit this flaw by submitting crafted requests to the user update API with manipulated builder.apps fields. This allows the attacker to escalate privileges and gain unauthorized builder access to other applications within the same tenant. The vulnerability enables lateral privilege escalation across unrelated apps in a multi-tenant environment. It has been assigned CVE-2026-82240 and is documented in both the NVD and GitHub security advisories. The fix is included in Budibase version 3.41.3 and later.

Affected products

  • Budibase

Related CVE's

  • CVE-2026-82240

Categories

  • Enterprise Applications
  • Identity & Access
  • Web Technologies