OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100684

HIGH · CVSS 8.1 EPSS 0.33% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Budibase versions 3.41.0 to 3.45.0 are vulnerable to an authentication bypass in the OIDC/SSO login process, allowing attackers to exploit pending user invites by asserting a victim's email address without proper validation. This vulnerability can lead to unauthorized access and full tenant compromise, enabling attackers to inherit privileges of the invited user, including builder and admin roles. Organizations using affected versions should prioritize patching this vulnerability to prevent potential account takeovers and data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100684
Severity
HIGH
CVSS
8.1
EPSS
0.33%

Original NVD Description

Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server. In sso.authenticate, when no existing user matches the incoming SSO subject, the server looks up pending user invites by the IdP-asserted email address alone — without validating an invite code and without an email_verified check (the email_verified gate protects only the existing-account lookup). An attacker who can register at an IdP that the tenant trusts for OIDC and assert a victim's invited email address (even with email_verified=false) claims the pending invite and inherits all of its granted privileges, including builder and admin.global, with no admin exclusion. This results in takeover of the invited principal and, for admin invites, full tenant compromise (access to all apps, datasources including production credentials, and automations); the invite is consumed, denying onboarding to the legitimate invitee.