Cross-Tenant Information Disclosure in Budibase Server
CVE-2026-100688
7.1HIGH
What is CVE-2026-100688?
Budibase server versions prior to 3.45.0 are susceptible to a cross-tenant information disclosure vulnerability through the GET /api/applications/:appId/appPackage endpoint. This issue allows authenticated users to exploit the system by accessing another tenant's application metadata and source code without proper authorization checks. Attackers can manipulate requests to retrieve sensitive details such as navigation structures, role names, internal screen URLs, and JavaScript snippets potentially exposing user identifiers, leading to significant privacy and security concerns.
Affected Version(s)
server 0 < 3.45.0
server 3.45.0
