PatchSiren cyber security CVE debrief
CVE-2026-100685 budibase CVE debrief
Budibase server versions before 3.45.0 improperly scope the GET /api/chat-links endpoint by workspace. This flaw allows builders with access to a single workspace to enumerate chat identity link records across all workspaces in a tenant. Sensitive data, including user IDs and external chat service identifiers, can be retrieved from workspaces the attacker has no permission to access.
- Vendor
- budibase
- Product
- server
- CVSS
- HIGH 8.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-26
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-09-26
- Advisory updated
- 2026-10-08
Who should care
Budibase administrators, security teams, and developers who use Budibase server should be aware of this vulnerability. They should assess their exposure and take necessary actions to mitigate the risk.
Why it matters
CVE-2026-100685 allows unauthorized data exposure in Budibase server versions before 3.45.0. Builders with access to one workspace can enumerate chat links across all workspaces, potentially exposing user IDs and external chat identifiers. Budibase administrators and security teams should prioritize updating to version 3.45.0 or later and restrict endpoint access to mitigate this high-severity vulnerability.
- Unauthorized enumeration of chat identity link records across workspaces
- Potential exposure of sensitive user data and external chat service identifiers
- Possible lateral movement within a tenant using builder access
- Need for verification of current Budibase server version and exposure
Technical summary
The Budibase server before version 3.45.0 has a vulnerability in the GET /api/chat-links endpoint. This endpoint is not properly scoped by workspace, allowing a builder with access to a single workspace to enumerate chat identity link records across all workspaces in a tenant. This can lead to the retrieval of sensitive chat identity linking data, including user IDs and external chat service identifiers, from other workspaces the builder has no permission to access.
Defensive priority
Budibase administrators and security teams should prioritize updating Budibase server to version 3.45.0 or later to mitigate this vulnerability. They should also review and restrict access to the /api/chat-links endpoint, ensuring that builders can only access chat identity link records within their authorized workspaces.
Recommended defensive actions
- Update Budibase server to version 3.45.0 or later
- Review and restrict access to the /api/chat-links endpoint
- Ensure builders can only access chat identity link records within authorized workspaces
- Verify current Budibase server version and exposure
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE Program record and NVD vulnerability detail provide official information about this vulnerability. Budibase's own security advisory and a VulnCheck advisory offer additional context. Affected Budibase server versions before 3.45.0 improperly scope the GET /api/chat-links endpoint by workspace, allowing builders with access to a single workspace to enumerate chat identity link records across all workspaces in a tenant. Sensitive data, including user IDs and external chat service identifiers, can be retrieved from workspaces the
Sources and references
Verified primary and authoritative sources
-
CVE-2026-100685 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-100685
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-100685 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100685
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Budibase before 3.45.0 Information Disclosure via Chat Links
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/100xxx/CVE-2026-100685.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/Budibase/budibase/security/advisories/GHSA-76m3-47v8-p7h6
Supplemental source - vendor-advisory
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/budibase-before-3.45.0-information-disclosure-via-chat-links
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.