Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 28 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Budibase before 3.41.3 fails to enforce role-based authorization on license management endpoints, allowing any authenticated user to delete license keys or manipulate offline tokens. Attackers with basic user privileges can access /api/global/license/* endpoints to disable premium features and downgrade deployments for all users. | |
| Title | Budibase before 3.41.3 Missing Authorization License Management | |
| First Time appeared |
Budibase
Budibase budibase |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:budibase:budibase:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Budibase
Budibase budibase |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-28T10:49:32.098Z
Reserved: 2026-08-28T10:37:51.949Z
Link: CVE-2026-82245
No data.
Status : Received
Published: 2026-08-28T12:16:35.000
Modified: 2026-08-28T12:16:35.000
Link: CVE-2026-82245
No data.
OpenCVE Enrichment
No data.
-
CWE-862
Missing Authorization