OIDC Flow Vulnerability in Budibase Open-Source Low-Code Platform
CVE-2026-73302

9CRITICAL

Key Information:

Vendor

Budibase

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-73302?

Budibase, an open-source low-code platform, contains a vulnerability in its OIDC flow prior to version 3.39.30. This issue arises when the email is resolved without verifying its status. An attacker could exploit this by authenticating through an identity provider that does not verify the user's email, allowing the attacker to link their fresh identity to the victim's Budibase account. This compromises the victim's roles and permissions. The vulnerability has been addressed in the latest release.

Affected Version(s)

budibase < 3.39.30

References

CVSS V4

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.