CVE-2026-100686
8.6
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Summary
Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endpoint, allowing builders to assign application roles across workspace boundaries. A builder of a single workspace can exploit missing per-app authorization checks to grant themselves admin roles in other workspaces by modifying user group role mappings.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| budibase | server | 0 < 3.45.0 | affected |
| budibase | server | 3.45.0 | unaffected |
Weaknesses
- CWE-269: Improper Privilege Management
References
- https://github.com/Budibase/budibase/security/advisories/GHSA-pp5r-q4fp-mcj3
- https://www.vulncheck.com/advisories/budibase-before-3.45.0-cross-workspace-privilege-escalation-via-post-api-global-groups-groupid-apps
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.