PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-73308 Budibase CVE debrief

CVE-2026-73308 Budibase Low-Code Platform Vulnerability. Budibase, an open-source low-code platform, had a vulnerability prior to version 3.39.25 that could expose OAuth2 access and refresh tokens of other SSO-authenticated builders. This issue allowed co-builders to potentially receive or poll automation test results and obtain these tokens. The vulnerability was fixed by adding sanitizeAutomationTestResult and isolating progress by user. Budibase users and security teams should assess exposure and update to version 3.39.25 or later.

Vendor
Budibase
Product
Unknown
CVSS
MEDIUM 5.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-12
Original CVE updated
2026-09-08
Advisory published
2026-08-12
Advisory updated
2026-09-08

Who should care

Budibase users, particularly those with multiple builders or co-builders, should assess their exposure and update to version 3.39.25 or later. Security teams responsible for low-code platforms and environments using Budibase should verify their inventory and prioritize remediation.

Why it matters

CVE-2026-73308 is a medium-severity vulnerability in Budibase that could allow co-builders to obtain OAuth2 tokens of other SSO-authenticated builders. Budibase users and security teams should assess exposure, prioritize updating to version 3.39.25 or later, and verify their inventory to address potential risks.

  • Potential exposure of OAuth2 access and refresh tokens
  • Risk of unauthorized access to automation test results
  • Need for verification of affected versions and remediation
  • Priority for updating to version 3.39.25 or later

Technical summary

The Budibase low-code platform had a vulnerability prior to version 3.39.25, where automation test results could expose OAuth2 access and refresh tokens of other SSO-authenticated builders. A co-builder could potentially receive or poll test results and obtain these tokens. The issue was fixed by adding sanitizeAutomationTestResult and isolating progress by user. This fix ensures that progress is isolated by user, preventing unauthorized access to automation test results and reducing the risk of OAuth2 token exposure.

Defensive priority

Budibase users should prioritize updating to version 3.39.25 or later to address the vulnerability.

Recommended defensive actions

  • Update Budibase to version 3.39.25 or later
  • Review and isolate progress by user in automation test results
  • Sanitize automation test results to prevent exposure of OAuth2 tokens
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE record and NVD entry provide details on the Budibase vulnerability, which allows a co-builder to potentially obtain OAuth2 access and refresh tokens of another SSO-authenticated builder. The issue is fixed in version 3.39.25.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-73308 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-73308

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-73308 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73308

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.