CVE-2026-82240
Received Received - Intake

Budibase Privilege Escalation via Unauthorized Builder Role Assignment

Vulnerability report for CVE-2026-82240, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-08-28

Assigner: VulnCheck

Description

Budibase before 3.41.3 fails to validate app-scoped builder role assignments in the public user create and update endpoints, allowing an authenticated app-scoped builder to grant builder access to unrelated apps. Attackers can submit crafted requests to the user update API with builder.apps fields to escalate privileges and gain unauthorized builder access to other applications in the same tenant.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-08-28
Generated
2026-08-28
AI Q&A
2026-08-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
budibase budibase to 3.41.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Budibase before version 3.41.3 has a flaw where it does not properly check app-scoped builder role assignments in public user create and update endpoints. This allows an authenticated builder to grant builder access to other unrelated apps within the same tenant by sending crafted requests to the user update API with builder.apps fields.

Detection Guidance

Check Budibase logs for unusual builder role assignments or unauthorized app access attempts. Monitor API requests to the user update endpoint for crafted builder.apps fields.

Impact Analysis

An attacker with builder access could escalate their privileges and gain unauthorized builder access to other applications in the same tenant. This could lead to data breaches, unauthorized modifications, or further lateral movement within the system.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, which may violate compliance requirements such as GDPR (data protection) and HIPAA (health information privacy). Organizations using affected Budibase versions may face regulatory penalties and reputational damage.

Mitigation Strategies

Upgrade Budibase to version 3.41.3 or later. Review and revoke any unauthorized builder role assignments. Implement strict input validation for API requests to the user update endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82240. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart