PatchSiren cyber security CVE debrief
CVE-2026-73308 Budibase CVE debrief
CVE-2026-73308 Budibase Low-Code Platform Vulnerability. Budibase, an open-source low-code platform, had a vulnerability prior to version 3.39.25 that could expose OAuth2 access and refresh tokens of other SSO-authenticated builders. This issue allowed co-builders to potentially receive or poll automation test results and obtain these tokens. The vulnerability was fixed by adding sanitizeAutomationTestResult and isolating progress by user. Budibase users and security teams should assess exposure and update to version 3.39.25 or later.
- Vendor
- Budibase
- Product
- Unknown
- CVSS
- MEDIUM 5.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-12
- Original CVE updated
- 2026-09-08
- Advisory published
- 2026-08-12
- Advisory updated
- 2026-09-08
Who should care
Budibase users, particularly those with multiple builders or co-builders, should assess their exposure and update to version 3.39.25 or later. Security teams responsible for low-code platforms and environments using Budibase should verify their inventory and prioritize remediation.
Why it matters
CVE-2026-73308 is a medium-severity vulnerability in Budibase that could allow co-builders to obtain OAuth2 tokens of other SSO-authenticated builders. Budibase users and security teams should assess exposure, prioritize updating to version 3.39.25 or later, and verify their inventory to address potential risks.
- Potential exposure of OAuth2 access and refresh tokens
- Risk of unauthorized access to automation test results
- Need for verification of affected versions and remediation
- Priority for updating to version 3.39.25 or later
Technical summary
The Budibase low-code platform had a vulnerability prior to version 3.39.25, where automation test results could expose OAuth2 access and refresh tokens of other SSO-authenticated builders. A co-builder could potentially receive or poll test results and obtain these tokens. The issue was fixed by adding sanitizeAutomationTestResult and isolating progress by user. This fix ensures that progress is isolated by user, preventing unauthorized access to automation test results and reducing the risk of OAuth2 token exposure.
Defensive priority
Budibase users should prioritize updating to version 3.39.25 or later to address the vulnerability.
Recommended defensive actions
- Update Budibase to version 3.39.25 or later
- Review and isolate progress by user in automation test results
- Sanitize automation test results to prevent exposure of OAuth2 tokens
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record and NVD entry provide details on the Budibase vulnerability, which allows a co-builder to potentially obtain OAuth2 access and refresh tokens of another SSO-authenticated builder. The issue is fixed in version 3.39.25.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-73308 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-73308
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-73308 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73308
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/Budibase/budibase/commit/bca426de7dc36d680285295655dc640dea2aab21
-
Source reference
Unverified legacy reference
URL: https://github.com/Budibase/budibase/pull/19107
-
Source reference
Unverified legacy reference
URL: https://github.com/Budibase/budibase/releases/tag/3.39.25
-
Source reference
Unverified legacy reference
URL: https://github.com/Budibase/budibase/security/advisories/GHSA-gh4h-34gr-87r7
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.