---
id: CVE-2026-82240
title: >-
  Budibase before 3.41.3 fails to validate app-scoped builder role assignments
  in the public user create and update endpoints, allowing an authenticated
  app-scoped builder to grant builder access to unrelated apps
summary: >-
  Budibase before 3.41.3 fails to validate app-scoped builder role assignments
  in the public user create and update endpoints, allowing an authenticated
  app-scoped builder to grant builder access to unrelated apps. Attackers can
  submit cra…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-862
vendor: budibase
product: server
affected:
  - server < 3.41.3
published: '2026-08-28'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:46.727'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82240'
references:
  - url: >-
      https://github.com/Budibase/budibase/security/advisories/GHSA-468g-55qj-v8rr
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/budibase-before-3.41.3-privilege-escalation-via-user-update-api
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-28T14:32:16.694088Z'
epss: 0.00363
epssPercentile: 0.2807
ingestedAt: '2026-10-08T16:52:14.732Z'
---

## Overview

Budibase before 3.41.3 fails to validate app-scoped builder role assignments in the public user create and update endpoints, allowing an authenticated app-scoped builder to grant builder access to unrelated apps. Attackers can submit crafted requests to the user update API with builder.apps fields to escalate privileges and gain unauthorized builder access to other applications in the same tenant.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
