CVE-2026-73304
Received Received - Intake

Budibase OAuth2 Token Exposure via Metadata API

Vulnerability report for CVE-2026-73304, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: GitHub, Inc.

Description

Budibase is an open-source low-code platform. Prior to 3.39.25, GET /api/users/metadata and GET /api/users/metadata/:id returned user objects processed by packages/server/src/utilities/global.ts without removing oauth2.accessToken or oauth2.refreshToken. A user with the POWER role could retrieve the identity-provider credentials of SSO-authenticated users and use the refresh tokens for persistent access to connected services. This issue is fixed in version 3.39.25.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-14
AI Q&A
2026-08-14
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
budibase budibase 3.39.25

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Budibase is an open-source low-code platform. A vulnerability in versions prior to 3.39.25 allowed GET requests to /api/users/metadata and /api/users/metadata/:id to return user objects containing OAuth2 access and refresh tokens. A user with the POWER role could exploit this to retrieve credentials of SSO-authenticated users and gain persistent access to connected services.

Impact Analysis

If you use Budibase versions before 3.39.25 with SSO authentication, an attacker with POWER role privileges could steal OAuth2 tokens. This allows them to impersonate users, access their connected services, and maintain unauthorized access even after password changes.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR's data protection principles and HIPAA's security requirements. It may result in data breaches, unauthorized disclosures, and failure to maintain confidentiality of sensitive information.

Mitigation Strategies

Upgrade Budibase to version 3.39.25 or later to address the issue. Review user access logs for unauthorized access attempts and revoke any compromised SSO tokens.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73304. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart