MEDIUMVulnerability

CVE-2026-73306

Budibase is an open-source low-code platform. Prior to 3.39.25, POST /api/global/auth/:tenantId/login incremented the failure counter in packages/worker/src/api/controllers/global/auth.ts only for existing users, while packages/worker/src/middleware/emailLockout.ts returned X-Account-Locked and Retry-After only for locked identifiers. An unauthenticated attacker could compare the response after repeated failures to enumerate valid email addresses and temporarily lock valid accounts. This issue is fixed in version 3.39.25.

Properties

severity
MEDIUM
score
5.3
epss_score
0.00321
cve_id
CVE-2026-73306
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
published_at
2026-08-12T20:17:54.270
last_modified
2026-09-08T20:56:50.520
epss_percentile
0.2468

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Observable Response Discrepancy

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-73306 — Ninja Signal Threat Intelligence | Ninja Signal