<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T04:08:50.818589+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-322247</id>
    <title>EUVD-2026-322247</title>
    <updated>2026-10-10T04:08:50.873175+00:00</updated>
    <content>EUVD-2026-322247</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-322247"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45716</id>
    <title>fkie_cve-2026-45716</title>
    <updated>2026-10-10T04:08:50.873213+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Budibase is an open-source low-code platform. Prior to 3.38.1, the POST /api/global/users/onboard endpoint is protected by workspaceBuilderOrAdmin middleware, allowing any user with builder permissions to access it. When SMTP email is not configured (the default for self-hosted Budibase instances), this endpoint bypasses the admin-restricted invite flow and directly creates users via bulkCreate, accepting arbitrary admin and builder role assignments from the request body. A builder-level user can create a new global admin account and receive the generated password in the response, achieving full privilege escalation. This vulnerability is fixed in 3.38.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-45716"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c54j-xp92-wh28</id>
    <title>GHSA-c54j-xp92-wh28 — Budibase: Builder-to-Admin Privilege Escalation via onboardUsers Endpoint Without SMTP Configuration</title>
    <updated>2026-10-10T04:08:50.873248+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @budibase/worker</p>
<p>## Summary</p>
<p>The `POST /api/global/users/onboard` endpoint is protected by `workspaceBuilderOrAdmin` middleware, allowing any user with builder permissions to access it. When SMTP email is not configured (the default for self-hosted Budibase instances), this endpoint bypasses the admin-restricted invite flow and directly creates users via `bulkCreate`, accepting arbitrary `admin` and `builder` role assignments from the request body. A builder-level user can create a new global admin account and receive the generated password in the response, achieving full privilege escalation.</p>
<p>## Details</p>
<p>The vulnerability stems from a mismatch between the authorization level of the `onboardUsers` endpoint and the user-creation capabilities it exposes when SMTP is not configured.</p>
<p>**Route definition** (`packages/worker/src/api/routes/global/users.ts:93-109`):
```typescript
builderOrAdminRoutes  // &lt;-- allows builders, not just admins
  .post(
    "/api/global/users/onboard",
    buildInviteMultipleValidation(),
    controller.onboardUsers
  )
```</p>
<p>Compare with the `invite` and `inviteMultiple` endpoints which are correctly admin-only:
```typescript
adminRoutes  // &lt;-- admin only
  .post("/api/global/users/invite", buildInviteValidation(), controller.invite)
  .post("/api/global/users/multi/invite", buildInviteMultipleValidation(), controller.inviteMultiple)
```</p>
<p>**Controller** (`packages/worker/src/api/controllers/global/users.ts:601-630`):
```typescript
export const onboardUsers = async (c…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c54j-xp92-wh28"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1477</id>
    <title>WID-SEC-W-2026-1477 — Budibase: Mehrere Schwachstellen</title>
    <updated>2026-10-10T04:08:50.873315+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Budibase ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Informationen offenzulegen, Code auszuführen oder seine Rechte zu erweitern.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1477"/>
  </entry>
</feed>
