HIGH 8.6 NVD
CVE-2026-100686
Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endpoint, allowing builders to assign applic
Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endpoint, allowing builders to assign application roles across workspace boundaries. A builder of a single workspace can exploit missing per-app authorization checks to grant themselves admin roles in other workspaces by modifying user group role mappings.
References
- https://github.com/Budibase/budibase/security/advisories/GHSA-pp5r-q4fp-mcj3
- https://www.vulncheck.com/advisories/budibase-before-3.45.0-cross-workspace-privilege-esca
This high severity vulnerability with a CVSS score of 8.6 was published on 2026-09-26 via NVD.
vulnfeed aggregates 11675 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.