Junglewise Threat Intelligence

CVE-2026-82239: Budibase authorization bypass in POST /api/datasources/query

CVE-2026-82239 · Severity: high · CVSS 8.1 · Published 2026-08-28

Technologies: Budibase. Vendors: Budibase.

Executive brief

Budibase is a low-code application platform that allows businesses to build and deploy internal tools and applications. A critical flaw in its data query API fails to enforce table-level permission restrictions, allowing low-privilege users to read, modify, or delete data in tables they should not have access to. This could expose sensitive business data, lead to unauthorized data manipulation, and compromise data integrity across applications built on the platform.

Technical details

The vulnerability is a missing authorization check (CWE-862) in the POST /api/datasources/query endpoint. The endpoint lacks a middleware call to populate ctx.resourceId with the target table identifier before the authorization check runs, causing the authorization middleware to fall back to a generic application-role check that does not evaluate per-table permissions. A BASIC-role user can submit a crafted JSON request specifying an arbitrary table's entityId and operation (READ, CREATE, UPDATE, or DELETE) to bypass per-table access controls. The normal row API (/api/:tableId/rows) correctly enforces these restrictions, but this alternate "raw query" endpoint does not. The vulnerability affects all versions of @budibase/server before 3.41.3 and has been patched in 3.41.3.

Affected products

  • Budibase Budibase before 3.41.3

Timeline

  • 2026-08-14: disclosed: Security advisory published on GitHub
  • 2026-08-28: advisory: NVD entry published
  • 2026-08-14: patched: Fixed in version 3.41.3

References