CVE-2026-25045: Budibase Critical Privilege Escalation & IDOR via Missing RBAC on User Role Management (Creator-Role)

Published Mar 9, 2026
·
Updated

Budibase is a low code platform for creating internal tools, workflows, and admin panels. This issue is a combination of Vertical Privilege Escalation and IDOR (Insecure Direct Object Reference) due to missing server-side RBAC checks in the /api/global/users endpoints. A Creator-level user, who should have no permissions to manage users or organizational roles, can instead promote an App Viewer to Tenant Admin, demote a Tenant Admin to App Viewer, or modify the Owner’s account details and all orders (e.g., change name). This is because the API accepts these actions without validating the requesting role, a Creator can replay Owner-only requests using their own session tokens. This leads to full tenant compromise.

Affected Software

2 affected components
budibase/budibase
budibase Budibase<=3.32.3

Event History

Mar 9, 2026
CVE Published
via MITRE·08:11 PM
Data Sourced
via MITRE·08:11 PM
DescriptionWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-25045?

CVE-2026-25045 has been classified as critical due to the potential for privilege escalation and data exposure.

2

How do I fix CVE-2026-25045?

To fix CVE-2026-25045, apply the latest patch provided by Budibase that addresses the RBAC and IDOR vulnerabilities.

3

What software is affected by CVE-2026-25045?

CVE-2026-25045 affects Budibase's low code platform specifically in its user role management system.

4

What type of vulnerabilities are associated with CVE-2026-25045?

CVE-2026-25045 involves vertical privilege escalation and insecure direct object reference (IDOR) vulnerabilities.

5

Can I safely use Budibase without addressing CVE-2026-25045?

It is not safe to use Budibase without addressing CVE-2026-25045, as it can lead to unauthorized access and data manipulation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203