SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-82245

HIGH · CVSS 8.1 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Budibase versions prior to 3.41.3 are vulnerable due to inadequate role-based authorization on license management endpoints, enabling authenticated users to delete license keys and manipulate offline tokens. This flaw allows attackers with basic privileges to access critical API endpoints, potentially disabling premium features and downgrading deployments for all users. Organizations using Budibase should prioritize patching to mitigate the risk of unauthorized access and disruption of service.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82245
Severity
HIGH
CVSS
8.1
EPSS
0.27%

Original NVD Description

Budibase before 3.41.3 fails to enforce role-based authorization on license management endpoints, allowing any authenticated user to delete license keys or manipulate offline tokens. Attackers with basic user privileges can access /api/global/license/* endpoints to disable premium features and downgrade deployments for all users.