PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-100685 budibase CVE debrief

Budibase server versions before 3.45.0 improperly scope the GET /api/chat-links endpoint by workspace. This flaw allows builders with access to a single workspace to enumerate chat identity link records across all workspaces in a tenant. Sensitive data, including user IDs and external chat service identifiers, can be retrieved from workspaces the attacker has no permission to access.

Vendor
budibase
Product
server
CVSS
HIGH 8.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-26
Original CVE updated
2026-10-08
Advisory published
2026-09-26
Advisory updated
2026-10-08

Who should care

Budibase administrators, security teams, and developers who use Budibase server should be aware of this vulnerability. They should assess their exposure and take necessary actions to mitigate the risk.

Why it matters

CVE-2026-100685 allows unauthorized data exposure in Budibase server versions before 3.45.0. Builders with access to one workspace can enumerate chat links across all workspaces, potentially exposing user IDs and external chat identifiers. Budibase administrators and security teams should prioritize updating to version 3.45.0 or later and restrict endpoint access to mitigate this high-severity vulnerability.

  • Unauthorized enumeration of chat identity link records across workspaces
  • Potential exposure of sensitive user data and external chat service identifiers
  • Possible lateral movement within a tenant using builder access
  • Need for verification of current Budibase server version and exposure

Technical summary

The Budibase server before version 3.45.0 has a vulnerability in the GET /api/chat-links endpoint. This endpoint is not properly scoped by workspace, allowing a builder with access to a single workspace to enumerate chat identity link records across all workspaces in a tenant. This can lead to the retrieval of sensitive chat identity linking data, including user IDs and external chat service identifiers, from other workspaces the builder has no permission to access.

Defensive priority

Budibase administrators and security teams should prioritize updating Budibase server to version 3.45.0 or later to mitigate this vulnerability. They should also review and restrict access to the /api/chat-links endpoint, ensuring that builders can only access chat identity link records within their authorized workspaces.

Recommended defensive actions

  • Update Budibase server to version 3.45.0 or later
  • Review and restrict access to the /api/chat-links endpoint
  • Ensure builders can only access chat identity link records within authorized workspaces
  • Verify current Budibase server version and exposure
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE Program record and NVD vulnerability detail provide official information about this vulnerability. Budibase's own security advisory and a VulnCheck advisory offer additional context. Affected Budibase server versions before 3.45.0 improperly scope the GET /api/chat-links endpoint by workspace, allowing builders with access to a single workspace to enumerate chat identity link records across all workspaces in a tenant. Sensitive data, including user IDs and external chat service identifiers, can be retrieved from workspaces the

Sources and references

Verified primary and authoritative sources

  • CVE-2026-100685 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-100685

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-100685 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100685

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Budibase before 3.45.0 Information Disclosure via Chat Links

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/100xxx/CVE-2026-100685.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Budibase/budibase/security/advisories/GHSA-76m3-47v8-p7h6

    Supplemental source - vendor-advisory

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/budibase-before-3.45.0-information-disclosure-via-chat-links

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.