CVE-2026-46425Patch

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Budibase is an open-source low-code platform. Prior to 3.38.2, packages/worker/src/api/routes/global/scim.ts attaches only two middlewares to the SCIM router: requireSCIM (checks the Enterprise feature flag and SCIM config) and doInScimContext (sets the SCIM request context). There is no role check. Any authenticated user who reaches the worker (BASIC role, workspace-scoped builder, anyone) can call SCIM endpoints and CRUD every user and group in the tenant. This vulnerability is fixed in 3.38.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-20); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-20: 1Mentions · 2026-05-27: 1Patch / Workaround · 2026-05-20: 1Technical Details · 2026-05-20: 105-2005-27
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-201
Patch1
2026-05-271
Disclosure1
Full discourse2 posts
  • Gray Hats@the_yellow_fall
    Patch

    Budibase patches a critical 9.9 CVSS SCIM authorization bypass (CVE-2026-46425). Basic users can delete admins and hijack accounts. Update now! #Budibase #CyberSecurity #InfoSec #CVE202646425 #VulnerabilityAlert #PrivilegeEscalation #PatchNow https://securityonline.info/budibase-scim-authorization-bypass-vulnerability-cve-2026-46425/

    Post summary

    The post announces a patch for the CVE‑2026‑46425 SCIM authorization bypass, provides technical details, and urges users to update.

    00002313
    12.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-46425 Budibase is an open-source low-code platform. Prior to 3.38.2, packages/worker/src/api/routes/global/scim.ts attaches only two middlewares to the SCIM router: require… https://www.cve.org/CVERecord?id=CVE-2026-46425

    Post summary

    The text announces CVE‑2026‑46425 affecting Budibase’s SCIM router prior to version 3.38.2, presenting a disclosure of a vulnerability without any PoC, exploit, or patch information.

    00000162
    57.5K followersView on X

Explore more