CVE-2026-100684
Received Received - Intake

Authentication Bypass in Budibase via OIDC/SSO Invite Abuse

Vulnerability report for CVE-2026-100684, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-26

Last updated on: 2026-09-26

Assigner: VulnCheck

Description

Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server. In sso.authenticate, when no existing user matches the incoming SSO subject, the server looks up pending user invites by the IdP-asserted email address alone β€” without validating an invite code and without an email_verified check (the email_verified gate protects only the existing-account lookup). An attacker who can register at an IdP that the tenant trusts for OIDC and assert a victim's invited email address (even with email_verified=false) claims the pending invite and inherits all of its granted privileges, including builder and admin.global, with no admin exclusion. This results in takeover of the invited principal and, for admin invites, full tenant compromise (access to all apps, datasources including production credentials, and automations); the invite is consumed, denying onboarding to the legitimate invitee.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-26
Last Modified
2026-09-26
Generated
2026-09-26
AI Q&A
2026-09-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
budibase server From 3.41.0 (inc) to 3.45.0 (exc)
budibase server From 3.41.0 (inc) to 3.44.9 (inc)
budibase server From 3.41.0 (inc) to 3.42.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Budibase versions 3.41.0 to 3.45.0 have an authentication bypass flaw in the OIDC/SSO login system. When a user tries to log in via SSO, the system checks for pending invites using only the email address from the identity provider without verifying an invite code or confirming the email is verified. An attacker can register with a trusted identity provider and claim a victim's pending invite by asserting the victim's email address, even if the email is not verified. This allows the attacker to gain the privileges associated with the invite, including admin rights, leading to full tenant compromise.

Impact Analysis

If you are a Budibase user running versions 3.41.0 to 3.45.0, an attacker could exploit this flaw to gain unauthorized access to your Budibase tenant. This could result in the attacker taking over admin accounts, accessing all applications and data sources, including sensitive production credentials, and running unauthorized automations. Legitimate users may also be denied access if their invites are claimed by attackers.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements under GDPR and HIPAA. If an attacker gains admin access, they could exfiltrate personal data, leading to regulatory fines and legal consequences. Organizations using Budibase must address this flaw to maintain compliance with data protection standards.

Mitigation Strategies

Upgrade Budibase to version 3.45.0 or later to address the authentication bypass in the OIDC/SSO login path. Review and revoke any suspicious admin or builder invites that may have been created due to this vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100684. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart