Medium severity4.3NVD Advisory· Published Aug 12, 2026
CVE-2026-73301
CVE-2026-73301
Description
Budibase is an open-source low-code platform. Prior to 3.39.25, the GET /api/global/groups endpoint in packages/worker/src/api/routes/global/groups.ts omitted auth.builderOrAdmin, allowing an authenticated BASIC role user to enumerate tenant groups, role mappings and user memberships, builder permissions, and default-group flags. The disclosure exposes the tenant access-control structure to users who are not builders or administrators. This issue is fixed in version 3.39.25.
Affected products
1Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.