What is CVE-2026-73304?
A critical vulnerability was discovered in the open-source low-code platform Budibase. In versions prior to 3.39.25, the /api/users/metadata endpoints returned user objects without removing OAuth2 accessToken or refreshToken, allowing a user with the POWER role to retrieve these sensitive tokens. Users should immediately upgrade to version 3.39.25 or later.
Azərbaycanca: Budibase açıq mənbəli low-code platformasında kritik bir boşluq aşkar edilib. 3.39.25 versiyasından əvvəlki versiyalarda, /api/users/metadata endpointləri OAuth2 accessToken və refreshToken məlumatlarını silmədən istifadəçi obyektlərini qaytarır, bu da POWER rolu olan istifadəçiyə həssas tokenləri əldə etməyə imkan verir. İstifadəçilər dərhal 3.39.25 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-200; shared vendor: Budibase
FAQ2
Which versions of Budibase are affected by the CVE-2026-73304 vulnerability?
All versions prior to 3.39.25 are affected by this vulnerability.
What sensitive data can an attacker obtain by exploiting CVE-2026-73304?
A user with the POWER role can retrieve other users' OAuth2 accessToken and refreshToken via the /api/users/metadata endpoints.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.