SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-82240

HIGH · CVSS 8.1 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Budibase versions prior to 3.41.3 are vulnerable due to inadequate validation of app-scoped builder role assignments, enabling authenticated users to exploit the public user create and update endpoints. This flaw allows attackers to escalate privileges by manipulating the user update API, potentially granting them unauthorized builder access to other applications within the same tenant. Organizations using Budibase should prioritize patching to mitigate the risk of privilege escalation and unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82240
Severity
HIGH
CVSS
8.1
EPSS
0.26%

Original NVD Description

Budibase before 3.41.3 fails to validate app-scoped builder role assignments in the public user create and update endpoints, allowing an authenticated app-scoped builder to grant builder access to unrelated apps. Attackers can submit crafted requests to the user update API with builder.apps fields to escalate privileges and gain unauthorized builder access to other applications in the same tenant.