Executive brief
Budibase is a low-code application platform used to build business applications. A flaw allows any authenticated user, including those with basic unprivileged accounts, to access and modify license management features that should be restricted to administrators. An attacker can delete the license key, disable premium security features (such as single sign-on and audit logging), or activate a different license key, affecting all users in the deployment.
Technical details
This is a missing authorization vulnerability (CWE-862) affecting the license management endpoints at /api/global/license/*. The vulnerable file (packages/worker/src/api/routes/global/license.ts) registers all license endpoints on loggedInRoutes, which enforces only authentication, not role-based authorization. The admin-level operations—including DELETE /api/global/license/key, POST /api/global/license/key (license activation), and DELETE /api/global/license/offline—lack the required adminOnly middleware that other sensitive routes use. An unauthenticated attacker cannot exploit this, but any logged-in user, even one with basic (lowest) privileges, can invoke these endpoints to degrade the deployment or replace licenses. The root cause stems from an oversight when license routes were created in March 2022 and mechanically preserved during a July 2025 refactoring. The vulnerability is patched in version 3.41.3.
Affected products
- Budibase Budibase before 3.41.3
Timeline
- 2026-08-14: disclosed: GitHub Security Advisory GHSA-4wr8-5c3p-rjcr published
- 2026-08-28: patched: Version 3.41.3 released with fix