CVE-2026-25040 Details
Description
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In versions up to and including 3.26.3, a Creator-level user, who normally has no UI permission to invite users, can manipulate API requests to invite new users with any role, including Admin, Creator, or App Viewer, and assign them to any group in the organization. This allows full privilege escalation, bypassing UI restrictions, and can lead to complete takeover of the workspace or organization. As of time of publication, no known fixed versions are available.
A critical privilege escalation vulnerability has been identified in Budibase versions through 3.26.3. This issue allows Creator-level users, who typically lack the permission to invite users, to manipulate API requests and invite new users with any role—Admin, Creator, or App Viewer. The vulnerability also enables assignment to any group within the organization, potentially leading to a complete takeover of the workspace or organization. The API fails to enforce role-based access controls, allowing unauthorized actions to go undetected.
Budibase should implement strict server-side role-based access control checks for all API endpoints that manage users, roles, or group memberships. Additionally, logging and alerting on privilege escalation attempts from low-privilege accounts could help detect and address such abuses.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://drive.google.com/file/d/1Dtn1WLJILRYUeoMjEbUfCbqQ3g2AW2Qz/view?usp=sharing | [email protected] | Exploit |
| https://github.com/Budibase/budibase/security/advisories/GHSA-4wfw-r86x-qxrm | [email protected] | ExploitVendor Advisory |
| https://github.com/user-attachments/files/22066135/budibase-privileged-esc-poc.txt | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| budibase budibase | <= 3.26.3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 3, 2026 | Initial Analysis | [email protected] |
| Jan 29, 2026 | New CVE Received | [email protected] |