PT-2026-44062 · Budibase · Budibase

Liyander

·

Published

2026-05-27

·

Updated

2026-06-12

·

CVE-2026-48151

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Budibase versions prior to 3.39.0
Description An issue exists in the open-source low-code platform where the webhook schema-building endpoint is registered under builderRoutes, but the generic authorization middleware fails to enforce authorization for all paths matching the "/api/webhooks/schema" endpoint. This allows an unauthenticated caller to update the body schema for a known webhook and mutate the corresponding automation trigger output schema.
Recommendations Update to version 3.39.0.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48151
GHSA-QHV3-WJG8-6FX6

Affected Products

Budibase