Impact
Budibase versions before 3.41.3 contain a flaw where role‑based authorization is not enforced on license‑management API endpoints. The missing check allows any authenticated user to call commands such as deleting license keys or altering offline tokens, effectively disabling premium features and downgrading the entire deployment. This capability directly compromises the integrity of the service and can be abused to nullify an organization’s paid features without permission.
Affected Systems
The vulnerable product is Budibase Server, any installation of Budibase prior to version 3.41.3. The issue affects all editions that rely on the default licensing framework published under the budibase:server vendor identifier.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity risk. Although the EPSS score is not available, the fact that any user with basic authentication can reach the endpoints means exploitation is straightforward and does not require additional privileges. The vulnerability is not currently listed in the CISA KEV catalog. The attack vector is inferred to be an authenticated user leveraging normal login credentials; no external network access or elevated privileges are required beyond those already granted to the user.
OpenCVE Enrichment