CVE-2026-72856Disclosure

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Budibase versions before 3.40.0 contain an authorization/authentication bypass in the PUT /api/global/users/tenant/owner (changeTenantOwnerEmail) endpoint. On self-hosted instances (SELF_HOSTED or DISABLE_ACCOUNT_PORTAL set), the cloudRestricted middleware is a no-op and the route is protected only by a general authentication check, so any authenticated user — including a lowest-privilege BASIC app user — can reassign the tenant account-holder (top-privilege admin) email to an attacker-controlled address. The attacker can then use the public password-reset flow to take over the admin account, leading to full administrative access.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-640

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-14: 1Technical Details · 2026-08-14: 108-14
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • NewNormal Security@NewScanTeam
    Disclosure

    NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 14 Aug 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 📦 Unauthenticated SQL injection in a low-code app platform — a webhook automation runs attacker SQL against the app's own database, no login (Budibase CVE-2026-72851, CVE-2026-72850, CVE-2026-72853, CVE-2026-72855, CVE-2026-72856, CVE-2026-72857, CVE-2026-72849, CVE-2026-72859, CVE-2026-73302, CVE-2026-73305, CVE-2026-73408) 📦 Signup takeover in a self-hosted file manager — on a case-insensitive filesystem, registering "Admin" lands in the existing admin's home directory (FileBrowser CVE-2026-72836) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #SQLi #CSO #REDTEAM

    Post summary

    NewNormal Security publishes a daily dump of newly added CVEs, providing brief vulnerability type descriptions but no exploitation code, active use evidence, or patch information.

    0000039
    5 followersView on X

Explore more