Privilege Escalation Vulnerability in Budibase Web Application by Budibase
CVE-2026-82240

8.6HIGH

Key Information:

Vendor

Budibase

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-82240?

In Budibase versions prior to 3.41.3, a critical vulnerability exists where the application fails to properly validate app-scoped builder role assignments in the public user create and update endpoints. This allows an authenticated user with builder permissions to manipulate the user update API by sending specially crafted requests that include builder.apps fields. As a result, this misconfiguration can be exploited to elevate privileges and gain unauthorized builder access to unrelated applications within the same tenant, posing a significant security risk.

Affected Version(s)

server 0 < 3.41.3

server 3.41.3

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

baradika
.