CVE-2026-82242 PUBLISHED

Budibase before 3.41.3 Cross-Application Resource Injection via Missing Authorization

Assigner: VulnCheck
Reserved: 28.08.2026 Published: 28.08.2026 Updated: 28.08.2026

Budibase versions before 3.41.3 contain a missing authorization vulnerability in the POST /api/resources/duplicate endpoint that allows authenticated builders to inject tables, automations, queries, and screens into any other application without holding any role in the destination workspace. Attackers can inject resources by specifying an arbitrary destination workspace ID in the request body, then trigger injected automations with outgoing webhooks to exfiltrate data from victim applications.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
CVSS Score: 8.3

Product Status

Vendor budibase
Product server
Versions Default: unaffected
  • affected from 0 to 3.41.3 (excl.)
  • Version 3.41.3 is unaffected

Credits

  • geo-chen reporter

References

Problem Types

  • Missing Authorization CWE