Cross-Site Request Forgery Vulnerability in Budibase by Budibase Inc.
CVE-2026-72849
8.7HIGH
What is CVE-2026-72849?
Budibase versions prior to 3.40.0 are affected by a cross-site request forgery vulnerability in the chat-link handoff endpoint. This vulnerability enables attackers to exploit a phishing page that can automatically submit a POST request with a stolen confirmation token. By doing so, they can link their external chat identity to a victim's account, leading to unauthorized impersonation and the inheritance of permissions associated with the victim's account during agent operations.
Affected Version(s)
server 0 < 3.40.0
server 3.40.0
