Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/query endpoint, allowing low-privilege BASIC users to read, create, update, or delete rows in any table regardless of configured permissions. Attackers with BASIC role can submit crafted query requests with target table identifiers to bypass table-level access controls and manipulate restricted data.
Metrics
Affected Vendors & Products
References
History
Fri, 28 Aug 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Budibase server
|
|
| Vendors & Products |
Budibase server
|
Fri, 28 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/query endpoint, allowing low-privilege BASIC users to read, create, update, or delete rows in any table regardless of configured permissions. Attackers with BASIC role can submit crafted query requests with target table identifiers to bypass table-level access controls and manipulate restricted data. | |
| Title | Budibase before 3.41.3 Authorization Bypass via datasources/query | |
| First Time appeared |
Budibase
Budibase budibase |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:budibase:budibase:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Budibase
Budibase budibase |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-08-28T10:49:28.004Z
Updated: 2026-08-28T15:44:26.965Z
Reserved: 2026-08-28T10:37:04.621Z
Link: CVE-2026-82239
No data.
Status : Deferred
Published: 2026-08-28T12:16:33.887
Modified: 2026-08-28T20:20:15.717
Link: CVE-2026-82239
No data.