CVE-2026-73303: Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)
Budibase is an open-source low-code platform. Prior to 3.40.0, POST /api/v2/email on account.budibase.app accepted a client-controlled accountId without binding it to the authenticated session, while checking only currentEmail. An authenticated attacker who obtains a victim account identifier can start the email-change workflow for the victim, receive and submit the verification code through POST /api/v2/email/verification, move the victim email to an attacker-controlled address, and complete a password reset as the victim. This issue is fixed in version 3.40.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Budibaseto a version that resolves this vulnerability.Fixed in 3.40.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73303?
CVE-2026-73303 has a severity score of 8.2, indicating it is high risk.
How do I fix CVE-2026-73303?
To remediate CVE-2026-73303, upgrade Budibase to version 3.40.0 or later.
What type of vulnerability is CVE-2026-73303?
CVE-2026-73303 is an Insecure Direct Object Reference (IDOR) vulnerability.
What impact can CVE-2026-73303 have on my account security?
CVE-2026-73303 can lead to full account takeover if an attacker exploits the vulnerability.
Which versions of Budibase are affected by CVE-2026-73303?
CVE-2026-73303 affects Budibase versions prior to 3.40.0.