


Perceptive Security
SOC/SIEM Consultancy

Budibase is an open-source low-code platform. Prior to 3.39.0, the single-datasource GET and PUT routes are guarded by generic TABLE READ, not by Builder/Admin …
Published:
26 May 2026 at 22:00:00
Alert date:
27 May 2026 at 20:13:42
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
Budibase open-source low-code platform prior to version 3.39.0 contains a privilege escalation vulnerability that allows Basic users to exploit inadequate permission checks on single-datasource GET and PUT routes. The vulnerability enables attackers to read REST datasource configurations, manipulate the config.url while preserving redacted authorization placeholders, and trigger relative-path REST queries. This results in server-side disclosure of builder-configured REST Authorization secrets to attacker-controlled listeners. The issue stems from routes being guarded by generic TABLE READ permissions rather than proper Builder/Admin permissions or datasource-specific ownership checks. Fixed in version 3.39.0.
Technical details
Mitigation steps:
Affected products:
Budibase
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-48152
https://github.com/Budibase/budibase/security/advisories/GHSA-3gp5-q4jw-3v94
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
