Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3192 articles · 168085 vulns · 37/41 feeds (7d)
← Back to list
7.3
CVE-2026-50132EXPLOITEDPATCHED
budiba · budibase

Budibase: Chat Identity Link Hijacking via Missing Consent & CSRF — Account Impersonation in Budibase

Description

Budibase is an open-source low-code platform. Prior to 3.39.0, `GET /api/chat-links/:instance/:token/handoff` is a public endpoint (no auth required) that performs a permanent, state-changing operation: it binds an external chat identity (Slack/Discord/MS Teams) to an authenticated Budibase user account, with no consent UI and no CSRF protection. The session token in the URL is created by the attacker (from their own /link slash command) and embeds the attacker's externalUserId. When an authenticated Budibase victim visits the URL, their account is silently and permanently linked to the attacker's Slack/Discord identity. The server responds with "Authentication succeeded." — no indication of what was linked. This vulnerability is fixed in 3.39.0.

Affected Products

VendorProductVersions
budibabudibase< 3.39.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourcebudibasecert_advisory90%

References

  • https://github.com/Budibase/budibase/security/advisories/GHSA-v7j5-vc4m-723w(x_refsource_CONFIRM)

Related News (2 articles)

Tier C
VulDB1d ago
CVE-2026-50132 | budibase up to 3.38.x Public Endpoint /api/chat-links access control
→ No new info (linked only)
Tier B
BSI Advisories4d ago
[NEU] [mittel] Budibase: Schwachstelle ermöglicht Manipulation von Daten
→ No new info (linked only)
CVSS 3.17.3 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
@budibase/server@3.39.0
CWECWE-284, CWE-352
PublishedJun 22, 2026
Last enriched1d agov2
Tags
GHSA-v7j5-vc4m-723wnpm
Trending Score49
Source articles2
Independent2
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-54350EXP
Budibase: Anonymous NoSQL operator injection via published-app query templates
Trending: 54
CRITICALCVE-2026-54353EXP
Budibase: Potential SSRF DNS rebinding bypass in outbound fetch validation
Trending: 44
HIGHCVE-2026-50137EXP
Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentials
Trending: 42
CRITICALCVE-2026-54352
Budibase: Arbitrary file read by workspace-builder via PWA-zip symlink upload
Trending: 39
CRITICALCVE-2026-50136
Budibase: Unauthenticated S3 signed upload URL generation allows arbitrary writes with stored datasource credentials
Trending: 35

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 22, 2026
Discovered by ZDM
Jun 22, 2026
Updated: vendor, affectedVersions, severity, activelyExploited
Jun 26, 2026
Actively Exploited
Jun 26, 2026
Patch Available
Jun 26, 2026

Version History

v2
Last enriched 1d ago
v2Tier C1d ago

Updated vendor to 'budibase', changed severity to CRITICAL, and added affected versions up to 3.38.x.

vendoraffectedVersionsseverityactivelyExploited
via VulDB
v15d ago

Initial creation