High severity8.1NVD Advisory· Published Sep 26, 2026
CVE-2026-100686
CVE-2026-100686
Description
Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endpoint, allowing builders to assign application roles across workspace boundaries. A builder of a single workspace can exploit missing per-app authorization checks to grant themselves admin roles in other workspaces by modifying user group role mappings.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.