---
id: CVE-2026-82242
title: >-
  Budibase versions before 3.41.3 contain a missing authorization vulnerability
  in the POST /api/resources/duplicate endpoint that allows authenticated
  builders to inject tables, automations, queries, and screens into any other
  application…
summary: >-
  Budibase versions before 3.41.3 contain a missing authorization vulnerability
  in the POST /api/resources/duplicate endpoint that allows authenticated
  builders to inject tables, automations, queries, and screens into any other
  application…
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N'
cwe:
  - CWE-862
vendor: budibase
product: server
affected:
  - server < 3.41.3
published: '2026-08-28'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:47.283'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82242'
references:
  - url: >-
      https://github.com/Budibase/budibase/security/advisories/GHSA-xqpq-288m-r5q7
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/budibase-before-3.41.3-cross-application-resource-injection-via-missing-authorization
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Budibase/budibase/security/advisories/GHSA-xqpq-288m-r5q7
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-28T14:02:45.467649Z'
epss: 0.00338
epssPercentile: 0.25189
ingestedAt: '2026-10-08T16:52:14.732Z'
---

## Overview

Budibase versions before 3.41.3 contain a missing authorization vulnerability in the POST /api/resources/duplicate endpoint that allows authenticated builders to inject tables, automations, queries, and screens into any other application without holding any role in the destination workspace. Attackers can inject resources by specifying an arbitrary destination workspace ID in the request body, then trigger injected automations with outgoing webhooks to exfiltrate data from victim applications.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
