CVE-2026-48151
HIGHBudibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schema
Title source: cnaDescription
Budibase is an open-source low-code platform. Prior to 3.39.0, the webhook schema-building endpoint is registered under builderRoutes, but the generic authorization middleware skips authorization for all paths matching /api/webhooks/schema. As a result, an unauthenticated caller can update the body schema for a known webhook and mutate the corresponding automation trigger output schema. This vulnerability is fixed in 3.39.0.
References (1)
Core 1
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/Budibase/budibase/security/advisories/GHSA-qhv3-wjg8-6fx6
Scores
CVSS v3
7.5
EPSS
0.0022
EPSS Percentile
12.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-862
Status
published
Products (2)
Budibase/budibase
< 3.39.0
budibase/server
0 - 3.39.0npm
Published
May 27, 2026
Tracked Since
May 27, 2026