CVE-2026-100684: Improper Authentication in budibase server
Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server. In sso.authenticate, when no existing user matches the incoming SSO subject, the server looks up pending user invites by the IdP-asserted email address alone — without validating an invite code and without an email_verified check (the email_verified gate protects only the existing-account lookup). An attacker who can register at an IdP that the tenant trusts for OIDC and assert a victim's invited email address (even with email_verified=false) claims the pending invite and inherits all of its granted privileges, including builder and admin.global, with no admin exclusion. This results in takeover of the invited principal and, for admin invites, full tenant compromise (access to all apps, datasources including production credentials, and automations); the invite is consumed, denying onboarding to the legitimate invitee.
AI Analysis
Technical Summary
CVE-2026-100684 is an authentication bypass vulnerability in Budibase server's OIDC/SSO login implementation affecting versions >=3.41.0 and <3.45.0. The vulnerability arises because the server's sso.authenticate function, when no existing user matches the incoming SSO subject, looks up pending user invites solely by the IdP-asserted email address without validating the invite code or checking if the email is verified. The email_verified check is only applied when matching existing accounts, not pending invites. An attacker able to register at a trusted IdP and assert a victim's invited email address—even with email_verified=false—can claim the pending invite and gain all associated privileges, including admin.global. This leads to takeover of the invited principal and full tenant compromise, exposing all apps, datasources (including production credentials), and automations. The invite is consumed, preventing the legitimate invitee from onboarding.
Potential Impact
Successful exploitation results in complete tenant takeover, including access to all applications, data sources with production credentials, and automation workflows. The attacker inherits all privileges granted by the pending invite, including administrative rights, and denies onboarding to the legitimate invited user. This compromises the confidentiality, integrity, and availability of the tenant's resources.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict or monitor registrations at trusted identity providers to prevent attackers from asserting victim email addresses. Review and tighten invite validation logic if possible. Avoid relying solely on email assertions without invite code and email verification checks.
CVE-2026-100684: Improper Authentication in budibase server
Description
Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server. In sso.authenticate, when no existing user matches the incoming SSO subject, the server looks up pending user invites by the IdP-asserted email address alone — without validating an invite code and without an email_verified check (the email_verified gate protects only the existing-account lookup). An attacker who can register at an IdP that the tenant trusts for OIDC and assert a victim's invited email address (even with email_verified=false) claims the pending invite and inherits all of its granted privileges, including builder and admin.global, with no admin exclusion. This results in takeover of the invited principal and, for admin invites, full tenant compromise (access to all apps, datasources including production credentials, and automations); the invite is consumed, denying onboarding to the legitimate invitee.
CVSS v4.0
Score 9.2critical
Affected software
budibase
server
pkg:github/budibase/serverRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-100684 is an authentication bypass vulnerability in Budibase server's OIDC/SSO login implementation affecting versions >=3.41.0 and <3.45.0. The vulnerability arises because the server's sso.authenticate function, when no existing user matches the incoming SSO subject, looks up pending user invites solely by the IdP-asserted email address without validating the invite code or checking if the email is verified. The email_verified check is only applied when matching existing accounts, not pending invites. An attacker able to register at a trusted IdP and assert a victim's invited email address—even with email_verified=false—can claim the pending invite and gain all associated privileges, including admin.global. This leads to takeover of the invited principal and full tenant compromise, exposing all apps, datasources (including production credentials), and automations. The invite is consumed, preventing the legitimate invitee from onboarding.
Potential Impact
Successful exploitation results in complete tenant takeover, including access to all applications, data sources with production credentials, and automation workflows. The attacker inherits all privileges granted by the pending invite, including administrative rights, and denies onboarding to the legitimate invited user. This compromises the confidentiality, integrity, and availability of the tenant's resources.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict or monitor registrations at trusted identity providers to prevent attackers from asserting victim email addresses. Review and tighten invite validation logic if possible. Avoid relying solely on email assertions without invite code and email verification checks.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-26T02:36:51.810Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab7c9abf7a7c5410652fd4f
Added to database: 09/26/2026, 13:33:31 UTC
Last enriched: 09/26/2026, 13:48:32 UTC
Last updated: 09/27/2026, 04:31:26 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.