CVE-2026-73304 | Budibase up to 3.39.24 User Object Processing global.ts oauth2.accessToken/oauth2.refreshToken privileges management

SecurityVulns

A vulnerability identified as problematic has been detected in Budibase up to 3.39.24. This impacts an unknown function of the file packages/server/src/utilities/global.ts of the component User Object Processing. Performing a manipulation of the argument oauth2.accessToken/oauth2.refreshToken results in improper privilege management.

This vulnerability is reported as CVE-2026-73304. The attack is possible to be carried out remotely. No exploit exists.

You should upgrade the affected component.VulDB Recent EntriesRead More