Information Exposure Vulnerability in Budibase Low-Code Platform
CVE-2026-73406
7.5HIGH
What is CVE-2026-73406?
Budibase, an open-source low-code platform, faced a vulnerability where its API endpoint allowed unauthorized access to sensitive user data. Prior to version 3.39.32, the endpoint GET /api/global/users/tenant/:id was included in PUBLIC_ENDPOINTS, exposing full PlatformUser documents. This flaw enabled unauthenticated requests to reveal email addresses, user identifiers, tenant identifiers, and document revision metadata. The issue has been resolved in the latest version, enhancing the platform's security.
Affected Version(s)
budibase < 3.39.32
