What is CVE-2026-73305?
CVE-2026-73305 is a vulnerability in the open-source low-code platform Budibase. In versions prior to 3.39.24, the `POST /api/public/v1/roles/assign` endpoint lacks proper `appId` validation in `validateGlobalRoleUpdate`, allowing an app-scoped builder to escalate privileges via crafted requests. Upgrading to version 3.39.24 or later is strongly recommended.
Azərbaycanca: CVE-2026-73305, Budibase açıq mənbəli low-code platformasında aşkarlanmış boşluqdur. 3.39.24 versiyasından əvvəl `POST /api/public/v1/roles/assign` endpointində `appId` yoxlaması aparılmadığı üçün app-scoped builder istifadəçisi sorğu vasitəsilə səlahiyyətlərini genişləndirə bilər. Dərhal 3.39.24 və ya daha yeni versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: Budibase
FAQ2
Which endpoint is exploited in the CVE-2026-73305 vulnerability in Budibase?
The vulnerability is exploited via the `POST /api/public/v1/roles/assign` endpoint.
What version of Budibase is recommended to mitigate CVE-2026-73305?
Upgrading to version 3.39.24 or later is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.