Get real-time updates on Telegram
CVE-2026-82240: server 0 to before 3.41.3
CVE-2026-82240. CVSS 3.1 base score 8.1 (HIGH, Vendor/CNA). EPSS 0.00363 (percentile 0.27988), scored 2026-10-06.
Affected technology
server · 0 to before 3.41.3
budibase
Description’s affected range: before 3.41.3 fails to validate app-scoped builder role assignments in the public user create and update endpoints
Component: Not specified by the source
Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · Low privileges required · No user interaction required
What an attacker can do
Attackers can submit crafted requests to the user update API with builder.apps fields to escalate privileges and gain unauthorized builder access to other applications in the same tenant. Vendor/CNA’s CVSS 4.0 assessment (base score 8.6/10) rates confidentiality and integrity impact as high; availability impact as none.
- CWE
- CWE-862
- CCR priority
- 32.5 /100 (P4)
- CVSS 3.1
- 8.1 /10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N · Vendor/CNA
- EPSS
- 0.00363 · percentile 0.28098 · 2026-10-08
- KEV
- no
Provenance
- FIRST EPSS daily exploit-probability · Source record · observed 2026-10-08 17:36:22.845483+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-08 17:32:11.049884+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-82240.html