HIGHVulnerability

CVE-2026-73305

Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRoleUpdate without checking appBuilder.appId or role.appId in packages/server/src/api/controllers/public/globalRoleValidation.ts. An app-scoped builder could scope the request to an app they control and then grant themselves builder access or an arbitrary role in another app, exposing that app data, datasource configuration, and automations. This issue is fixed in version 3.39.24.

Properties

severity
HIGH
score
8.8
cve_id
CVE-2026-73305
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
published_at
2026-08-13T22:17:25.657
last_modified
2026-08-18T02:17:28.797

Related Entities (4)

HAS_WEAKNESS (3)

[Weakness]Incorrect Authorization
[Weakness]Missing Authorization
[Weakness]Improper Privilege Management

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-73305 — Ninja Signal Threat Intelligence | Ninja Signal