๐Ÿ” CVE Alert

CVE-2026-100685

HIGH 7.7

Budibase before 3.45.0 Information Disclosure via Chat Links

CVSS Score
7.7
EPSS Score
0.0%
EPSS Percentile
0th

Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowing builders to enumerate chat identity link records across all workspaces in a tenant. Attackers with builder access to a single workspace can retrieve sensitive chat identity linking data including user IDs and external chat service identifiers from other workspaces they have no permission to access.

CWE CWE-863
Vendor budibase
Product server
Published Sep 26, 2026
Stay Ahead of the Next One

Get instant alerts for budibase server

Be the first to know when new high vulnerabilities affecting budibase server are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

budibase / server
0 < 3.45.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Budibase/budibase/security/advisories/GHSA-76m3-47v8-p7h6 vulncheck.com: https://www.vulncheck.com/advisories/budibase-before-3.45.0-information-disclosure-via-chat-links

Credits

๐Ÿ” Sagarrchauhann