CVE-2026-73301

MEDIUM CVSS 3.1: 4.3 EPSS 0.25%
Updated Aug 15, 2026
Budibase
Parameter Value
CVSS 4.3 (MEDIUM)
Fixed In 3.39.25
Type CWE-862 (Missing Authorization)
Vendor Budibase
Public PoC No

Budibase is an open-source low-code platform. Prior to 3.39.25, the GET /api/global/groups endpoint in packages/worker/src/api/routes/global/groups.ts omitted auth.builderOrAdmin, allowing an authenticated BASIC role user to enumerate tenant groups, role mappings and user memberships, builder permissions, and default-group flags. The disclosure exposes the tenant access-control structure to users who are not builders or administrators.

This issue is fixed in version 3.39.25.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1

Vulnerable Products

budibase:budibase