Low-Code Platform Vulnerability in Budibase Affects User Authentication and Token Security
CVE-2026-73308
5.7MEDIUM
What is CVE-2026-73308?
Budibase, an open-source low-code platform, has a vulnerability in its automation testing module that exposes sensitive OAuth2 access and refresh tokens. Prior to version 3.39.25, test results returned by the platform included unscoped user outputs, which could be accessed by co-builders. This flaw allows unauthorized users to poll another SSO-authenticated builder's test, compromising confidentiality and security within shared environments. The issue has been addressed in version 3.39.25 by implementing proper user scoping and sanitization of test results.
Affected Version(s)
budibase < 3.39.25
