Budibase versions before 3.41.3 fail to enforce role-based authorization on license management API endpoints. Any authenticated user, regardless of privilege level, can access /api/global/license/* endpoints. This allows attackers with basic user accounts to delete license keys or manipulate offline tokens. The impact includes disabling premium features and downgrading deployments for all users organization-wide. The vulnerability is classified as a missing authorization (broken access control) issue. It requires only valid authentication credentials to exploit, lowering the barrier for abuse. Affected organizations could experience service degradation and loss of paid functionality. The fix is available in Budibase version 3.41.3 and later.