logo

Keys to the Kingdom: Critical 9.9 CVSS Budibase Flaw Allows Total Tenant Takeover

ID: ebcad4b0-f104-58f0-9a56-8e1aa0d1de1a

STIX ID: report--ebcad4b0-f104-58f0-9a56-8e1aa0d1de1a

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Ddos

...
...

Budibase disclosed a critical authorization-bypass vulnerability (CVE-2026-46425, CVSS ~9.9) in its SCIM endpoints where role-based checks were omitted; any authenticated user in tenants with SCIM enabled could list, create, modify, or delete users and groups, enabling PII exposure, account takeover, admin deletion, and role escalation. The issue affects versions prior to 3.38.2 and has been fixed in 3.38.2 — administrators are advised to update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.