


Perceptive Security
SOC/SIEM Consultancy

Budibase before 3.41.3 fails to enforce role-based authorization on license management endpoints, allowing any authenticated user to delete license keys or mani…
Published:
28 augustus 2026 om 00:00:00
Alert date:
28 augustus 2026 om 15:08:13
Source:
nvd.nist.gov
Enterprise Applications, Identity & Access, Web Technologies
CVE-2026-82245 affects Budibase versions prior to 3.41.3, where role-based authorization is not enforced on license management API endpoints. Any authenticated user, regardless of privilege level, can access /api/global/license/* endpoints. This allows attackers with basic user accounts to delete license keys or manipulate offline tokens. The practical impact includes disabling premium features and downgrading deployments for all users of the affected instance. The vulnerability is classified as a missing authorization (broken access control) issue. It has been patched in Budibase version 3.41.3. The issue is documented in both the NVD and GitHub Security Advisories, as well as VulnCheck. Organizations running self-hosted or cloud Budibase instances below 3.41.3 should upgrade immediately. The vulnerability could be leveraged for denial-of-service against premium functionality or sabotage of enterprise deployments.
Technical details
Mitigation steps:
Affected products:
Budibase before 3.41.3
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-82245
https://github.com/Budibase/budibase/security/advisories/GHSA-4wr8-5c3p-rjcr
https://www.vulncheck.com/advisories/budibase-before-3.41.3-missing-authorization-license-management
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
