๐Ÿ” CVE Alert

CVE-2026-72849

HIGH 7.7

Budibase before 3.40.0 Identity Confusion via Chat-Link Handoff CSRF

CVSS Score
7.7
EPSS Score
0.0%
EPSS Percentile
0th

Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff endpoint that allows attackers to bind an external chat identity to a victim's account. Attackers can craft a phishing page that auto-submits a POST request with a leaked confirmation token to bind their chat identity to a victim user's account, enabling impersonation within agent operations and inheritance of victim permissions.

CWE CWE-352
Vendor budibase
Product server
Published Aug 13, 2026
Stay Ahead of the Next One

Get instant alerts for budibase server

Be the first to know when new high vulnerabilities affecting budibase server are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

budibase / server
0 < 3.40.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Budibase/budibase/security/advisories/GHSA-pvcr-8mvp-w8qr vulncheck.com: https://www.vulncheck.com/advisories/budibase-before-identity-confusion-via-chat-link-handoff-csrf

Credits

๐Ÿ” hypnguyen1209