CVE-2026-25045Disclosure(budibase / budibase)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Budibase is a low code platform for creating internal tools, workflows, and admin panels. This issue is a combination of Vertical Privilege Escalation and IDOR (Insecure Direct Object Reference) due to missing server-side RBAC checks in the /api/global/users endpoints. A Creator-level user, who should have no permissions to manage users or organizational roles, can instead promote an App Viewer to Tenant Admin, demote a Tenant Admin to App Viewer, or modify the Owner’s account details and all orders (e.g., change name). This is because the API accepts these actions without validating the requesting role, a Creator can replay Owner-only requests using their own session tokens. This leads to full tenant compromise.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • budibase

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
budibase

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-09: 2Technical Details · 2026-03-09: 103-09
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25045 Vertical Privilege Escalation and IDOR in Budibase Platform User Management API https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25045

    Post summary

    The text announces CVE-2026-25045, noting vertical privilege escalation and IDOR vulnerabilities in the Budibase Platform User Management API, accompanied by a link to vulnerability details.

    0000044
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-25045 Budibase is a low code platform for creating internal tools, workflows, and admin panels. This issue is a combination of Vertical Privilege Escalation and IDOR (Insec… https://www.cve.org/CVERecord?id=CVE-2026-25045

    Post summary

    The post references CVE-2026-25045 in Budibase, indicating it involves vertical privilege escalation and IDOR, but it does not mention PoC, exploit code, active exploitation, or patch details.

    0000083
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbudibasebudibase---

Explore more