CVE-2026-50132Disclosure(budibase / budibase)

LOWCVSS 7.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Budibase is an open-source low-code platform. Prior to 3.39.0, `GET /api/chat-links/:instance/:token/handoff` is a public endpoint (no auth required) that performs a permanent, state-changing operation: it binds an external chat identity (Slack/Discord/MS Teams) to an authenticated Budibase user account, with no consent UI and no CSRF protection. The session token in the URL is created by the attacker (from their own /link slash command) and embeds the attacker's externalUserId. When an authenticated Budibase victim visits the URL, their account is silently and permanently linked to the attacker's Slack/Discord identity. The server responds with "Authentication succeeded." — no indication of what was linked. This vulnerability is fixed in 3.39.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-352

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • budibase

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-26); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
budibase

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-26: 2Mentions · 2026-06-27: 1Technical Details · 2026-06-26: 2Technical Details · 2026-06-27: 106-2606-27
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-262
Disclosure2
2026-06-271
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-50132 Budibase is an open-source low-code platform. Prior to 3.39.0, `GET /api/chat-links/:instance/:token/handoff` is a public endpoint (no auth required) that performs a … https://www.cve.org/CVERecord?id=CVE-2026-50132

    Post summary

    The post announces CVE-2026-50132 in Budibase, detailing an unauthenticated public API endpoint vulnerability, with no PoC, exploit, patch, or active exploitation mentioned.

    000101.0K
    57.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-50132 Unauthenticated Account Linking via CSRF in Budibase Prior to 3.39.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-50132

    Post summary

    A newly disclosed CVE (2026-50132) describes an unauthenticated CSRF‑based account linking flaw affecting Budibase versions older than 3.39.0.

    00000113
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-50132 Budibase is an open-source low-code platform. Prior to 3.39.0, `GET /api/chat-links/:instance/:token/handoff` is a public endpoint (no auth required) that performs a … https://www.cve.org/CVERecord?id=CVE-2026-50132 ----- Traducción: CVE-2026-50132 Bud… http://infoflow.cloud`

    Post summary

    The passage announces CVE-2026-50132 for Budibase, noting that before version 3.39.0 a public, unauthenticated endpoint exists, but it does not provide a PoC, exploit, or patch details.

    0000038
    89 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbudibasebudibase---

Explore more