Cross-Workspace Privilege Escalation in Budibase by Budibase
CVE-2026-100686

8.6HIGH

Key Information:

Vendor

Budibase

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100686?

Budibase versions prior to 3.45.0 are vulnerable due to inadequate validation of per-app authorization in the POST /api/global/groups/:groupId/apps endpoint. This flaw allows users within a single workspace to exploit the absence of proper authorization checks, enabling them to grant themselves elevated admin roles across different workspaces by simply altering user group role mappings. The issue raises significant security concerns, especially for environments requiring strict access controls.

Affected Version(s)

server 0 < 3.45.0

server 3.45.0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

moratoantoine
.