CVE-2026-73406 | Budibase up to 3.39.31 User Lookup API Endpoint index.ts tenantUserLookup ID information disclosure
A vulnerability identified as problematic has been detected in Budibase up to 3.39.31. Impacted is the function tenantUserLookup of the file packages/worker/src/api/index.ts of the component User Lookup API Endpoint. This manipulation of the argument ID causes information disclosure.
This vulnerability is handled as CVE-2026-73406. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.VulDB Recent EntriesRead More