Low-Code Platform Vulnerability in Budibase Affects User Authentication and Token Security
CVE-2026-73308

5.7MEDIUM

Key Information:

Vendor

Budibase

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-73308?

Budibase, an open-source low-code platform, has a vulnerability in its automation testing module that exposes sensitive OAuth2 access and refresh tokens. Prior to version 3.39.25, test results returned by the platform included unscoped user outputs, which could be accessed by co-builders. This flaw allows unauthorized users to poll another SSO-authenticated builder's test, compromising confidentiality and security within shared environments. The issue has been addressed in version 3.39.25 by implementing proper user scoping and sanitization of test results.

Affected Version(s)

budibase < 3.39.25

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.