Sensitive Data Exposure in Budibase Low-Code Platform
CVE-2026-73304
4.9MEDIUM
What is CVE-2026-73304?
Budibase, an open-source low-code platform, has a vulnerability where certain API endpoints, specifically GET /api/users/metadata and GET /api/users/metadata/:id, expose sensitive information. Prior to version 3.39.25, these endpoints returned user objects containing sensitive information, including oauth2.accessToken and oauth2.refreshToken. A user with elevated privileges (POWER role) could exploit this flaw to access the identity-provider credentials of SSO-authenticated users, enabling the use of refresh tokens for ongoing access to connected services. This security issue has been addressed in version 3.39.25.
Affected Version(s)
budibase < 3.39.25
