<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T17:08:24.074449+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-351976</id>
    <title>EUVD-2026-351976</title>
    <updated>2026-10-03T17:08:24.077833+00:00</updated>
    <content>EUVD-2026-351976</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-351976"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73406</id>
    <title>fkie_cve-2026-73406</title>
    <updated>2026-10-03T17:08:24.077864+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/users/tenant/:id was listed in PUBLIC_ENDPOINTS in packages/worker/src/api/index.ts, and tenantUserLookup returned a full PlatformUser document. An unauthenticated caller could query an email or user identifier, distinguish existing users from missing users, and obtain tenant identifiers, user identifiers, email addresses, SSO identifiers, and document revision metadata. This issue is fixed in version 3.39.32.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-73406"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hr66-5mqr-8mpx</id>
    <title>GHSA-hr66-5mqr-8mpx — Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint</title>
    <updated>2026-10-03T17:08:24.077896+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @budibase/server</p>
<p>#### Summary
The Budibase Worker service exposes a public, unauthenticated API endpoint (`GET /api/global/users/tenant/:id`) that returns sensitive user information including `tenantId`, `userId`, `email`, and `ssoId`. The endpoint is registered in the `PUBLIC_ENDPOINTS` list with a `TODO` comment acknowledging it "should be an internal API." Any unauthenticated party can enumerate user emails or IDs to extract sensitive tenant and user metadata, enabling targeted attacks against multi-tenant deployments.</p>
<p>#### Details</p>
<p>**Public endpoint registration** at `packages/worker/src/api/index.ts` lines 56-59:</p>
<p>```typescript
// TODO: This should be an internal api
{
  route: "/api/global/users/tenant/:id",
  method: "GET",
},
```</p>
<p>This endpoint is listed in `PUBLIC_ENDPOINTS`, which is passed to `auth.buildAuthMiddleware(PUBLIC_ENDPOINTS)` at line 154. When a request matches a public endpoint pattern, the authentication middleware sets `ctx.publicEndpoint = true` and calls `next()` without performing any authentication (verified at `packages/backend-core/src/middleware/authenticated.ts` lines 124-126, 249-251).</p>
<p>All subsequent middleware also skips for public endpoints:
- `buildTenancyMiddleware` — passes through
- `activeTenant` — passes through
- `buildCsrfMiddleware` — skipped for GET methods (line 48 of csrf.ts)
- The `budibaseAccess` gate at lines 160-168 explicitly returns `next()` when `ctx.publicEndpoint` is true</p>
<p>**Route registration** at `packages/worker/src/api/routes/glo…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hr66-5mqr-8mpx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2483</id>
    <title>WID-SEC-W-2026-2483 — Budibase: Mehrere Schwachstellen</title>
    <updated>2026-10-03T17:08:24.077966+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Budibase ausnutzen, um erweiterte Berechtigungen zu erlangen, SQL-Injection durchzuführen, Sicherheitsmaßnahmen zu umgehen, Konten zu übernehmen, Daten zu manipulieren oder offenzulegen sowie einen Denial-of-Service-Zustand auszulösen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2483"/>
  </entry>
</feed>
