Junglewise Threat Intelligence

CVE-2026-100686: Budibase cross-workspace privilege escalation in group apps endpoint

CVE-2026-100686 · Severity: high · CVSS 8.1 · Published 2026-09-26

Technologies: Budibase Server. Vendors: Budibase.

Executive brief

Budibase is a low-code platform for building business applications. A builder in one workspace can exploit a missing authorization check in the user group management API to grant themselves admin roles in other workspaces they don't have access to, breaking isolation between separate workspace environments. This allows an attacker to access and potentially modify data in workspaces they should not be able to reach.

Technical details

The POST /api/global/groups/:groupId/apps endpoint uses the weaker builderOrAdmin guard instead of adminOnly like other group mutation endpoints, and fails to validate that the caller is a builder of each target appId before writing role mappings. The builderOrAdmin middleware cannot determine workspace context from nested add[].appId in the request body, allowing a builder of any workspace to satisfy the authorization check while modifying roles in workspaces they don't build. Exploitation requires USER_GROUPS feature to be enabled (Team/Business/Enterprise tiers).

Affected products

  • Budibase Budibase Server before 3.45.0

Timeline

  • 2026-09-26: disclosed
  • 2026-09-26: patched: patched in version 3.45.0

References

Related threats