在 Budibase 3.41.3 之前的版本中,公共的用户创建和更新接口未能正确校验应用范围(app-scoped)的构建者(builder)角色分配,导致拥有应用范围内构建者权限的认证用户能够将构建者权限授予不相关的应用。攻击者可以通过向用户更新 API 提交精心构造的请求,并包含 字段,从而提升权限,并获得同一租户下其他应用的未授权构建者访问权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82244 | 9.1 CRITICAL | Budibase before 3.41.3 Remote Code Execution via Plugin eval() |
| CVE-2026-82245 | 8.1 HIGH | Budibase before 3.41.3 Missing Authorization License Management |
| CVE-2026-82239 | 8.1 HIGH | Budibase before 3.41.3 Authorization Bypass via datasources/query |
| CVE-2026-82242 | 7.7 HIGH | Budibase before 3.41.3 Cross-Application Resource Injection via Missing Authorization |
| CVE-2026-82243 | 7.6 HIGH | Budibase Server before 3.41.3 SSRF with Credential Leakage |
| CVE-2026-82246 | 7.1 HIGH | Budibase Server before 3.41.3 SSRF via Query Import |
| CVE-2026-82241 | 7.1 HIGH | Budibase backend-core SSRF via incomplete default blacklist |
No comments yet