high · CVSS v3 8.1 · CVSS v4 8.6
CVE-2026-100686
Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endp…
Description
Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endpoint, allowing builders to assign application roles across workspace boundaries. A builder of a single workspace can exploit missing per-app authorization checks to grant themselves admin roles in other workspaces by modifying user group role mappings.
Scores
- Severity
- high
- CVSS v2
- 8.5
- CVSS v3
- 8.1
- CVSS v4
- 8.6
- EPSS
- —