CVE-2026-73302
Received Received - Intake

Authentication Bypass in Budibase via Unverified OIDC Email

Vulnerability report for CVE-2026-73302, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: GitHub, Inc.

Description

Budibase is an open-source low-code platform. Prior to 3.39.30, the OIDC flow in packages/backend-core/src/middleware/passport/sso/oidc.ts resolved an email without getEmailVerified or an email_verified requirement, and packages/backend-core/src/middleware/passport/sso/sso.ts then used users.getGlobalUserByEmail as a fallback account-linking key. An attacker who can authenticate through a configured identity provider that asserts a victim email as unverified can have a fresh provider identity merged into the victim Budibase account and inherit the victim roles. This issue is fixed in version 3.39.30.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-14
AI Q&A
2026-08-14
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
budibase budibase to 3.39.30 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Budibase, an open-source low-code platform. It allows an attacker to merge a fresh provider identity into a victim's Budibase account using an unverified email from an identity provider. The attacker can then inherit the victim's roles and permissions.

Impact Analysis

If you use Budibase versions before 3.39.30, an attacker could gain unauthorized access to your account by exploiting this flaw. They could perform actions on your behalf, access sensitive data, or perform administrative tasks if they inherit elevated roles.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR's data protection principles or HIPAA's security requirements. It may result in non-compliance, legal penalties, or reputational damage due to data breaches.

Mitigation Strategies

Upgrade Budibase to version 3.39.30 or later to address the vulnerability. Review OIDC configurations to ensure email verification is enforced before account linking.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73302. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart