top of page
perceptive_background_267k.jpg

Budibase before 3.41.3 fails to enforce role-based authorization on license management endpoints, allowing any authenticated user to delete license keys or mani…

Published:

28 augustus 2026 om 00:00:00

Alert date:

28 augustus 2026 om 15:08:13

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Identity & Access, Web Technologies

CVE-2026-82245 affects Budibase versions prior to 3.41.3, where role-based authorization is not enforced on license management API endpoints. Any authenticated user, regardless of privilege level, can access /api/global/license/* endpoints. This allows attackers with basic user accounts to delete license keys or manipulate offline tokens. The practical impact includes disabling premium features and downgrading deployments for all users of the affected instance. The vulnerability is classified as a missing authorization (broken access control) issue. It has been patched in Budibase version 3.41.3. The issue is documented in both the NVD and GitHub Security Advisories, as well as VulnCheck. Organizations running self-hosted or cloud Budibase instances below 3.41.3 should upgrade immediately. The vulnerability could be leveraged for denial-of-service against premium functionality or sabotage of enterprise deployments.

Technical details

Mitigation steps:

Affected products:

Budibase before 3.41.3

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page