Loading market data...
← Back to CVE feed

CVE-2026-100686

HIGH CVSS 8.1 View on NVD ↗

Description

Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endpoint, allowing builders to assign application roles across workspace boundaries. A builder of a single workspace can exploit missing per-app authorization checks to grant themselves admin roles in other workspaces by modifying user group role mappings.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Published: Sep 26, 2026 14:16 UTC Modified: Sep 26, 2026 14:16 UTC