What is CVE-2026-72856?
Budibase versions prior to 3.40.0 contain an authorization/authentication bypass vulnerability in the PUT /api/global/users/tenant/owner endpoint. On self-hosted instances where SELF_HOSTED or DISABLE_ACCOUNT_PORTAL is set, the cloudRestricted middleware becomes a no-op, leaving the route insufficiently protected. Immediate update to version 3.40.0 is recommended.
Azərbaycanca: Budibase platformasının 3.40.0 versiyasından əvvəlki versiyalarında "PUT /api/global/users/tenant/owner" endpoint-də avtorizasiya və autentifikasiya bypass zəifliyi mövcuddur. Bu, xüsusilə "SELF_HOSTED" və ya "DISABLE_ACCOUNT_PORTAL" parametrləri aktiv olan instansiyalarda "cloudRestricted" middleware-in təsirsiz qalması səbəbindən yaranır. Dərhal 3.40.0 versiyasına yenilənmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which versions of Budibase are affected by CVE-2026-72856?
All versions prior to 3.40.0 are affected.
Under what conditions can this vulnerability be exploited?
On instances where SELF_HOSTED or DISABLE_ACCOUNT_PORTAL is set, the cloudRestricted middleware becomes a no-op, leaving the PUT /api/global/users/tenant/owner endpoint unprotected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.