---
id: CVE-2026-82239
title: >-
  Budibase before 3.41.3 fails to enforce per-table role restrictions on the
  POST /api/datasources/query endpoint, allowing low-privilege BASIC users to
  read, create, update, or delete rows in any table regardless of configured
  permissions…
summary: >-
  Budibase before 3.41.3 fails to enforce per-table role restrictions on the
  POST /api/datasources/query endpoint, allowing low-privilege BASIC users to
  read, create, update, or delete rows in any table regardless of configured
  permissions…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-862
vendor: budibase
product: server
affected:
  - server < 3.41.3
published: '2026-08-28'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:46.580'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82239'
references:
  - url: >-
      https://github.com/Budibase/budibase/security/advisories/GHSA-vq3j-xwg3-pg8x
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/budibase-before-3.41.3-authorization-bypass-via-datasources-query
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Budibase/budibase/security/advisories/GHSA-vq3j-xwg3-pg8x
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-08-28T15:44:04.214482Z'
epss: 0.00386
epssPercentile: 0.30494
ingestedAt: '2026-10-08T16:52:14.731Z'
---

## Overview

Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/query endpoint, allowing low-privilege BASIC users to read, create, update, or delete rows in any table regardless of configured permissions. Attackers with BASIC role can submit crafted query requests with target table identifiers to bypass table-level access controls and manipulate restricted data.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
