CVE-2026-82240 PUBLISHED

Budibase before 3.41.3 Privilege Escalation via User Update API

Assigner: VulnCheck
Reserved: 28.08.2026 Published: 28.08.2026 Updated: 28.08.2026

Budibase before 3.41.3 fails to validate app-scoped builder role assignments in the public user create and update endpoints, allowing an authenticated app-scoped builder to grant builder access to unrelated apps. Attackers can submit crafted requests to the user update API with builder.apps fields to escalate privileges and gain unauthorized builder access to other applications in the same tenant.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.6

Product Status

Vendor budibase
Product server
Versions Default: unaffected
  • affected from 0 to 3.41.3 (excl.)
  • Version 3.41.3 is unaffected

Credits

  • baradika reporter

References

Problem Types

  • Missing Authorization CWE