Description
Budibase before 3.41.3 fails to validate app-scoped builder role assignments in the public user create and update endpoints, allowing an authenticated app-scoped builder to grant builder access to unrelated apps. Attackers can submit crafted requests to the user update API with builder.apps fields to escalate privileges and gain unauthorized builder access to other applications in the same tenant.
Published: 2026-08-28
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via incorrect role assignment
Action: Immediate Patch
AI Analysis

Impact

Budibase before version 3.41.3 does not validate app-scoped builder role assignments in the public user create and update APIs. An authenticated user with an app-scoped builder role can submit a request that includes a builder.apps field, granting builder access to any application within the same tenant. This flaw allows the attacker to receive builder privileges for unrelated apps, enabling them to edit, publish, or delete application content without authorization.

Affected Systems

The vulnerability affects Budibase server deployments running any version prior to 3.41.3. Users of the Budibase v3.x series that have not applied the 3.41.3 patch are at risk.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog. The likely attack path requires an authenticated app‑scoped builder to access the public user update endpoint and supply crafted builder.apps data. If the role assignment mechanism is bypassed, the attacker can gain unauthorized builder access to other applications within the same tenant, potentially leading to full application compromise.

Generated by OpenCVE AI on August 28, 2026 at 13:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Budibase server to version 3.41.3 or later, which adds validation for builder role assignments during user creation and update.
  • If a patch cannot be applied immediately, limit or revoke the public user update API for app‑scoped builder roles, or restrict a builder’s ability to modify builder.apps fields until the fix is in place.
  • Enable detailed audit logging for user updates and actively monitor for unexpected changes to builder.app assignments to detect and respond to potential exploitation.

Generated by OpenCVE AI on August 28, 2026 at 13:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Budibase server
Vendors & Products Budibase server

Fri, 28 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Description Budibase before 3.41.3 fails to validate app-scoped builder role assignments in the public user create and update endpoints, allowing an authenticated app-scoped builder to grant builder access to unrelated apps. Attackers can submit crafted requests to the user update API with builder.apps fields to escalate privileges and gain unauthorized builder access to other applications in the same tenant.
Title Budibase before 3.41.3 Privilege Escalation via User Update API
First Time appeared Budibase
Budibase budibase
Weaknesses CWE-862
CPEs cpe:2.3:a:budibase:budibase:*:*:*:*:*:*:*:*
Vendors & Products Budibase
Budibase budibase
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Budibase Budibase Server
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-28T15:52:56.424Z

Reserved: 2026-08-28T10:37:04.621Z

Link: CVE-2026-82240

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-28T12:16:34.030

Modified: 2026-08-28T20:20:15.830

Link: CVE-2026-82240

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T15:45:02Z

Weaknesses