Privilege Escalation Vulnerability in Budibase Low Code Platform
CVE-2026-25040
What is CVE-2026-25040?
In Budibase, a low code platform designed for building internal tools, a serious vulnerability has been identified that allows Creator-level users to bypass established UI restrictions. Specifically, these users can manipulate API requests to invite new users across various roles including Admin, Creator, or App Viewer, and can assign them to any group within the organization. This significant oversight leads to potential full privilege escalation, enabling unauthorized access and control over the workspace or organization. No known fixed versions have been released as of the latest update, leaving users potentially exposed.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
budibase <= 3.26.3
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
