Low-Code Platform Vulnerability in Budibase by Budibase
CVE-2026-45718

5.4MEDIUM

Key Information:

Vendor

Budibase

Status
Vendor
CVE Published:
27 May 2026

What is CVE-2026-45718?

Budibase, a popular open-source low-code platform, has an authorization bypass vulnerability in its row action trigger endpoint. In versions preceding 3.38.1, the platform fails to properly validate the user-supplied rowId against the view's row filters. This allows users with access to a filtered view to execute row actions on any record within the underlying table, including those rows that are meant to be excluded by the security filters of the view. Users should upgrade to version 3.38.1 or later to mitigate this issue.

Affected Version(s)

budibase < 3.38.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.