What is CVE-2026-73302?
In Budibase open-source low-code platform before version 3.39.30, the OIDC flow fails to require email verification (email_verified). This could allow account takeover via unverified emails, users should urgently upgrade to the latest version.
Azərbaycanca: Budibase açıq mənbəli low-code platformasında, 3.39.30 versiyasından əvvəlki versiyalarda OIDC autentifikasiya axınında e-poçtun təsdiqlənməsi (email_verified) tələb olunmur. Bu, təsdiqlənməmiş e-poçtla hesab ələ keçirməyə imkan yaradır, təcili olaraq ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
What security issue was discovered in the OIDC authentication flow of the Budibase platform?
In Budibase versions before 3.39.30, the OIDC flow fails to require email_verified, which could allow account takeover via unverified emails.
What is the recommended action to protect against CVE-2026-73302?
Users are strongly advised to urgently upgrade the Budibase platform to the latest version, specifically 3.39.30 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.