AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-72849

HIGH · CVSS 7.7 EPSS 0.12% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

Budibase versions prior to 3.40.0 are vulnerable to a cross-site request forgery (CSRF) flaw in the chat-link handoff endpoint, allowing attackers to associate an external chat identity with a victim's account. This exploitation can lead to unauthorized impersonation within agent operations and the inheritance of victim permissions, posing significant risks to user data and operational integrity. Organizations using affected versions should prioritize patching to mitigate potential impersonation and security breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-72849
Severity
HIGH
CVSS
7.7
EPSS
0.12%

Original NVD Description

Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff endpoint that allows attackers to bind an external chat identity to a victim's account. Attackers can craft a phishing page that auto-submits a POST request with a leaked confirmation token to bind their chat identity to a victim user's account, enabling impersonation within agent operations and inheritance of victim permissions.