What is CVE-2026-73301?
CVE-2026-73301 affects the open-source low-code platform Budibase. In versions prior to 3.39.25, a missing authorization check on the GET /api/global/groups endpoint allows authenticated users with a BASIC role to enumerate tenant groups, role mappings, and user memberships. Updating to the latest version is recommended to remediate this information disclosure vulnerability.
Azərbaycanca: CVE-2026-73301 Budibase açıq mənbəli low-code platformasında müəyyən edilib. 3.39.25 versiyasından əvvəlki versiyalarda, autentifikasiya edilmiş sadə BASIC roluna malik istifadəçi `/api/global/groups` endpoint-i vasitəsilə tenant qruplarını, rol təyinatlarını və istifadəçi üzvlüklərini sadalaya bilir. Bu problemi aradan qaldırmaq üçün Budibase-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of Budibase are affected by CVE-2026-73301?
All versions of Budibase prior to 3.39.25 are affected by this vulnerability.
What type of information can be exposed by exploiting CVE-2026-73301?
An authenticated user with a BASIC role can enumerate tenant groups, role mappings, and user memberships via this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.