Impact
Budibase before version 3.41.3 does not validate app-scoped builder role assignments in the public user create and update APIs. An authenticated user with an app-scoped builder role can submit a request that includes a builder.apps field, granting builder access to any application within the same tenant. This flaw allows the attacker to receive builder privileges for unrelated apps, enabling them to edit, publish, or delete application content without authorization.
Affected Systems
The vulnerability affects Budibase server deployments running any version prior to 3.41.3. Users of the Budibase v3.x series that have not applied the 3.41.3 patch are at risk.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog. The likely attack path requires an authenticated app‑scoped builder to access the public user update endpoint and supply crafted builder.apps data. If the role assignment mechanism is bypassed, the attacker can gain unauthorized builder access to other applications within the same tenant, potentially leading to full application compromise.
OpenCVE Enrichment