CVE-2026-73305Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRoleUpdate without checking appBuilder.appId or role.appId in packages/server/src/api/controllers/public/globalRoleValidation.ts. An app-scoped builder could scope the request to an app they control and then grant themselves builder access or an arbitrary role in another app, exposing that app data, datasource configuration, and automations. This issue is fixed in version 3.39.24.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269CWE-862CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-14: 1Technical Details · 2026-08-14: 108-14
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • NewNormal Security@NewScanTeam
    Disclosure

    NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 14 Aug 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 📦 Unauthenticated SQL injection in a low-code app platform — a webhook automation runs attacker SQL against the app's own database, no login (Budibase CVE-2026-72851, CVE-2026-72850, CVE-2026-72853, CVE-2026-72855, CVE-2026-72856, CVE-2026-72857, CVE-2026-72849, CVE-2026-72859, CVE-2026-73302, CVE-2026-73305, CVE-2026-73408) 📦 Signup takeover in a self-hosted file manager — on a case-insensitive filesystem, registering "Admin" lands in the existing admin's home directory (FileBrowser CVE-2026-72836) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #SQLi #CSO #REDTEAM

    Post summary

    The daily CVE report lists several newly identified vulnerabilities, including unauthenticated SQL injection in Budibase and signup takeover in FileBrowser, but provides no exploit, patch, or PoC information.

    0000039
    5 followersView on X

Explore more