CVSS
4.3
CVSS v3.1
EPSS
N/A
Exploit Prediction Score
Published
August 12, 2026
Exploitability
No EPSS data available
Budibase is an open-source low-code platform. Prior to 3.39.25, the GET /api/global/groups endpoint in packages/worker/src/api/routes/global/groups.ts omitted auth.builderOrAdmin, allowing an authenticated BASIC role user to enumerate tenant groups, role mappings and user memberships, builder permissions, and default-group flags. The disclosure exposes the tenant access-control structure to users who are not builders or administrators. This issue is fixed in version 3.39.25.
No package data available.
Publisher and database URLs for this record (shown for attribution; reading stays in Bugflare).