Privilege Escalation Vulnerability in Budibase Low Code Platform
CVE-2026-25040

5.7MEDIUM

Key Information:

Vendor

Budibase

Status
Vendor
CVE Published:
29 January 2026

What is CVE-2026-25040?

In Budibase, a low code platform designed for building internal tools, a serious vulnerability has been identified that allows Creator-level users to bypass established UI restrictions. Specifically, these users can manipulate API requests to invite new users across various roles including Admin, Creator, or App Viewer, and can assign them to any group within the organization. This significant oversight leads to potential full privilege escalation, enabling unauthorized access and control over the workspace or organization. No known fixed versions have been released as of the latest update, leaving users potentially exposed.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

budibase <= 3.26.3

References

CVSS V4

Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.