OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100686

HIGH · CVSS 8.1 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Budibase versions prior to 3.45.0 are vulnerable due to inadequate validation of per-app authorization in the POST /api/global/groups/:groupId/apps endpoint, enabling users to manipulate role assignments across different workspaces. This flaw allows a builder to elevate their privileges by granting themselves admin roles in other workspaces, potentially compromising sensitive data and operations. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized access and privilege escalation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100686
Severity
HIGH
CVSS
8.1
EPSS
0.21%

Original NVD Description

Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endpoint, allowing builders to assign application roles across workspace boundaries. A builder of a single workspace can exploit missing per-app authorization checks to grant themselves admin roles in other workspaces by modifying user group role mappings.