CVE-2026-42239: Budibase auth session cookies are set with httpOnly:false — any XSS can lead to full account takeover

Published May 7, 2026
·
Updated

Budibase is an open-source low-code platform. Prior to version 3.35.10, the budibase:auth cookie containing the JWT session token is set with httpOnly: false at packages/backend-core/src/utils/utils.ts:218. JavaScript can read this cookie via document.cookie. This means every XSS becomes a full account takeover — the attacker steals the JWT and has persistent access to the victim's account. The cookie also lacks secure: true (sent over plaintext HTTP) and sameSite attribute. This issue has been patched in version 3.35.10.

Affected Software

2 affected components
budibase Budibase<3.35.10
budibase Budibase<3.35.10

Event History

May 7, 2026
CVE Published
via MITRE·06:49 PM
Data Sourced
via MITRE·06:49 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-42239?

CVE-2026-42239 has a high severity rating due to the potential for unauthorized account takeover through XSS attacks.

2

How do I fix CVE-2026-42239?

To fix CVE-2026-42239, update Budibase to version 3.35.10 or higher.

3

What impact does CVE-2026-42239 have on users?

CVE-2026-42239 allows attackers to exploit XSS vulnerabilities to hijack user sessions and take over accounts.

4

Which versions of Budibase are affected by CVE-2026-42239?

Budibase versions prior to 3.35.10 are affected by CVE-2026-42239.

5

What specific vulnerability does CVE-2026-42239 address?

CVE-2026-42239 addresses the vulnerability where the budibase:auth cookie is set with httpOnly: false, making it susceptible to theft via XSS.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203