CVE-2026-82239 is an authorization bypass vulnerability in Budibase versions prior to 3.41.3. The flaw exists in the POST /api/datasources/query endpoint, which fails to enforce per-table role-based access controls. Low-privilege BASIC users can exploit this by submitting crafted query requests containing target table identifiers, effectively bypassing configured table-level permissions. This allows attackers to perform unauthorized read, create, update, or delete operations on any table within the application. The vulnerability represents a significant access control failure in the Budibase low-code platform. A fix has been released in version 3.41.3. Advisories have been published on GitHub Security Advisories and VulnCheck.