Junglewise Threat Intelligence

CVE-2026-73305: Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRoleUpdate without che

CVE-2026-73305 · Severity: high · CVSS 8.8 · Published 2026-08-13

Technologies: @budibase/server (npm), Budibase Server. Vendors: npm, Budibase.

Executive brief

Budibase is a low-code platform for building web applications. An app-scoped builder (a developer with permission to modify specific apps only) can exploit a missing authorization check in the public API's role-assignment endpoint to grant themselves builder access to any other app in the system, or assign themselves admin privileges on any application. This allows an attacker to read, modify, and delete data in apps they were never authorized to access, steal database credentials, and modify automations.

Technical details

The vulnerability is a missing app-level authorization check in the POST /api/public/v1/roles/assign endpoint. The validation function validateGlobalRoleUpdate() only checks for global admin and builder flags but fails to validate app-scoped authorization parameters (appBuilder and role). An authenticated app-scoped builder can call this endpoint with x-budibase-app-id set to an app they control, allowing the authorization middleware to pass. The endpoint then forwards unvalidated appBuilder and role parameters to the SDK, which applies them without verifying the caller has authority over the target apps. An attacker can self-issue a public API key via POST /api/global/self/api_key (which incorrectly accepts app-scoped builders) and then invoke the roles endpoint to escalate themselves to builder or admin of arbitrary apps. The fix is available in version 3.40.0.

Affected products

  • Budibase server <3.40.0

Timeline

  • 2026-07-24: disclosed
  • 2026-07-24: patched: version 3.40.0

References

Related threats