CVE-2026-42239Disclosure(budibase / budibase)

LOWCVSS 8.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch budibase budibase systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Budibase is an open-source low-code platform. Prior to version 3.35.10, the budibase:auth cookie containing the JWT session token is set with httpOnly: false at packages/backend-core/src/utils/utils.ts:218. JavaScript can read this cookie via document.cookie. This means every XSS becomes a full account takeover — the attacker steals the JWT and has persistent access to the victim's account. The cookie also lacks secure: true (sent over plaintext HTTP) and sameSite attribute. This issue has been patched in version 3.35.10.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1004

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • budibase

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
budibase

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-07: 2Patch / Workaround · 2026-05-07: 1Technical Details · 2026-05-07: 205-07
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-42239 Budibase is an open-source low-code platform. Prior to version 3.35.10, the budibase:auth cookie containing the JWT session token is set with httpOnly: false at packa… https://www.cve.org/CVERecord?id=CVE-2026-42239

    Post summary

    Budibase’s low‑code platform has a cookie‑related security flaw (httpOnly: false) affecting versions before 3.35.10, as documented in CVE-2026-42239. No PoC, exploit, or active exploitation is reported, but upgrading to 3.35.10 mitigates the issue.

    00010141
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42239 Session Token Exposure via Insecure Cookie Configuration in Budibase Before 3.35.10 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42239

    Post summary

    CVE-2026-42239 describes session token exposure in Budibase versions prior to 3.35.10; the text provides no evidence of exploitation, tools, or patches.

    0000048
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbudibasebudibase---

Explore more