Information Exposure Vulnerability in Budibase Low-Code Platform
CVE-2026-73406

7.5HIGH

Key Information:

Vendor

Budibase

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-73406?

Budibase, an open-source low-code platform, faced a vulnerability where its API endpoint allowed unauthorized access to sensitive user data. Prior to version 3.39.32, the endpoint GET /api/global/users/tenant/:id was included in PUBLIC_ENDPOINTS, exposing full PlatformUser documents. This flaw enabled unauthenticated requests to reveal email addresses, user identifiers, tenant identifiers, and document revision metadata. The issue has been resolved in the latest version, enhancing the platform's security.

Affected Version(s)

budibase < 3.39.32

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.