Skip to main content

CVE-2026-100684: Improper Authentication in budibase server

0
Critical
Published: 09/26/2026 (09/26/2026, 15:31:20 UTC)
Source: CVE Database V5
Vendor/Project: budibase
Product: server

Description

Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server. In sso.authenticate, when no existing user matches the incoming SSO subject, the server looks up pending user invites by the IdP-asserted email address alone — without validating an invite code and without an email_verified check (the email_verified gate protects only the existing-account lookup). An attacker who can register at an IdP that the tenant trusts for OIDC and assert a victim's invited email address (even with email_verified=false) claims the pending invite and inherits all of its granted privileges, including builder and admin.global, with no admin exclusion. This results in takeover of the invited principal and, for admin invites, full tenant compromise (access to all apps, datasources including production credentials, and automations); the invite is consumed, denying onboarding to the legitimate invitee.

CVSS v4.0

Score 9.2critical

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
High
Vuln. Availability
High
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected software

budibase

server

Affected versions
>=3.41.0 <3.45.0
GitHub Actionsmore threats →ai
budibase/server
pkg:github/budibase/server
Affected versions
>=3.41.0 <3.45.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/26/2026, 13:48:32 UTC

Technical Analysis

CVE-2026-100684 is an authentication bypass vulnerability in Budibase server's OIDC/SSO login implementation affecting versions >=3.41.0 and <3.45.0. The vulnerability arises because the server's sso.authenticate function, when no existing user matches the incoming SSO subject, looks up pending user invites solely by the IdP-asserted email address without validating the invite code or checking if the email is verified. The email_verified check is only applied when matching existing accounts, not pending invites. An attacker able to register at a trusted IdP and assert a victim's invited email address—even with email_verified=false—can claim the pending invite and gain all associated privileges, including admin.global. This leads to takeover of the invited principal and full tenant compromise, exposing all apps, datasources (including production credentials), and automations. The invite is consumed, preventing the legitimate invitee from onboarding.

Potential Impact

Successful exploitation results in complete tenant takeover, including access to all applications, data sources with production credentials, and automation workflows. The attacker inherits all privileges granted by the pending invite, including administrative rights, and denies onboarding to the legitimate invited user. This compromises the confidentiality, integrity, and availability of the tenant's resources.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict or monitor registrations at trusted identity providers to prevent attackers from asserting victim email addresses. Review and tighten invite validation logic if possible. Avoid relying solely on email assertions without invite code and email verification checks.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
VulnCheck
Date Reserved
2026-09-26T02:36:51.810Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6ab7c9abf7a7c5410652fd4f

Added to database: 09/26/2026, 13:33:31 UTC

Last enriched: 09/26/2026, 13:48:32 UTC

Last updated: 09/27/2026, 04:31:26 UTC

Views: 14

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses