OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100685

HIGH · CVSS 7.7 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Budibase versions prior to 3.45.0 are vulnerable due to improper scoping of the GET /api/chat-links endpoint, which allows attackers with builder access in one workspace to enumerate sensitive chat identity link records across all workspaces within a tenant. This could lead to unauthorized access to user IDs and external chat service identifiers, posing a significant risk to user privacy and data security. Organizations using Budibase should prioritize patching this vulnerability to prevent potential data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100685
Severity
HIGH
CVSS
7.7
EPSS
0.21%

Original NVD Description

Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowing builders to enumerate chat identity link records across all workspaces in a tenant. Attackers with builder access to a single workspace can retrieve sensitive chat identity linking data including user IDs and external chat service identifiers from other workspaces they have no permission to access.