<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 00:28:51 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-351976</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-351976</link>
      <description>EUVD-2026-351976</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-351976</guid>
    </item>
    <item>
      <title>fkie_cve-2026-73406</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73406</link>
      <description>&lt;p&gt;Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/users/tenant/:id was listed in PUBLIC_ENDPOINTS in packages/worker/src/api/index.ts, and tenantUserLookup returned a full PlatformUser document. An unauthenticated caller could query an email or user identifier, distinguish existing users from missing users, and obtain tenant identifiers, user identifiers, email addresses, SSO identifiers, and document revision metadata. This issue is fixed in version 3.39.32.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/users/tenant/:id was listed in PUBLIC_ENDPOINTS in packages/worker/src/api/index.ts, and tenantUserLookup returned a full PlatformUser document. An unauthenticated caller could query an email or user identifier, distinguish existing users from missing users, and obtain tenant identifiers, user identifiers, email addresses, SSO identifiers, and document revision metadata. This issue is fixed in version 3.39.32.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-73406</guid>
    </item>
    <item>
      <title>GHSA-hr66-5mqr-8mpx — Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hr66-5mqr-8mpx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @budibase/server&lt;/p&gt;
&lt;p&gt;#### Summary
The Budibase Worker service exposes a public, unauthenticated API endpoint (`GET /api/global/users/tenant/:id`) that returns sensitive user information including `tenantId`, `userId`, `email`, and `ssoId`. The endpoint is registered in the `PUBLIC_ENDPOINTS` list with a `TODO` comment acknowledging it &amp;#34;should be an internal API.&amp;#34; Any unauthenticated party can enumerate user emails or IDs to extract sensitive tenant and user metadata, enabling targeted attacks against multi-tenant deployments.&lt;/p&gt;
&lt;p&gt;#### Details&lt;/p&gt;
&lt;p&gt;**Public endpoint registration** at `packages/worker/src/api/index.ts` lines 56-59:&lt;/p&gt;
&lt;p&gt;```typescript
// TODO: This should be an internal api
{
  route: &amp;#34;/api/global/users/tenant/:id&amp;#34;,
  method: &amp;#34;GET&amp;#34;,
},
```&lt;/p&gt;
&lt;p&gt;This endpoint is listed in `PUBLIC_ENDPOINTS`, which is passed to `auth.buildAuthMiddleware(PUBLIC_ENDPOINTS)` at line 154. When a request matches a public endpoint pattern, the authentication middleware sets `ctx.publicEndpoint = true` and calls `next()` without performing any authentication (verified at `packages/backend-core/src/middleware/authenticated.ts` lines 124-126, 249-251).&lt;/p&gt;
&lt;p&gt;All subsequent middleware also skips for public endpoints:
- `buildTenancyMiddleware` — passes through
- `activeTenant` — passes through
- `buildCsrfMiddleware` — skipped for GET methods (line 48 of csrf.ts)
- The `budibaseAccess` gate at lines 160-168 explicitly returns `next()` when `ctx.publicEndpoint` is true&lt;/p&gt;
&lt;p&gt;**Route registration** at `packages/worker/src/api/routes/glo…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @budibase/server&lt;/p&gt;
&lt;p&gt;#### Summary
The Budibase Worker service exposes a public, unauthenticated API endpoint (`GET /api/global/users/tenant/:id`) that returns sensitive user information including `tenantId`, `userId`, `email`, and `ssoId`. The endpoint is registered in the `PUBLIC_ENDPOINTS` list with a `TODO` comment acknowledging it &amp;#34;should be an internal API.&amp;#34; Any unauthenticated party can enumerate user emails or IDs to extract sensitive tenant and user metadata, enabling targeted attacks against multi-tenant deployments.&lt;/p&gt;
&lt;p&gt;#### Details&lt;/p&gt;
&lt;p&gt;**Public endpoint registration** at `packages/worker/src/api/index.ts` lines 56-59:&lt;/p&gt;
&lt;p&gt;```typescript
// TODO: This should be an internal api
{
  route: &amp;#34;/api/global/users/tenant/:id&amp;#34;,
  method: &amp;#34;GET&amp;#34;,
},
```&lt;/p&gt;
&lt;p&gt;This endpoint is listed in `PUBLIC_ENDPOINTS`, which is passed to `auth.buildAuthMiddleware(PUBLIC_ENDPOINTS)` at line 154. When a request matches a public endpoint pattern, the authentication middleware sets `ctx.publicEndpoint = true` and calls `next()` without performing any authentication (verified at `packages/backend-core/src/middleware/authenticated.ts` lines 124-126, 249-251).&lt;/p&gt;
&lt;p&gt;All subsequent middleware also skips for public endpoints:
- `buildTenancyMiddleware` — passes through
- `activeTenant` — passes through
- `buildCsrfMiddleware` — skipped for GET methods (line 48 of csrf.ts)
- The `budibaseAccess` gate at lines 160-168 explicitly returns `next()` when `ctx.publicEndpoint` is true&lt;/p&gt;
&lt;p&gt;**Route registration** at `packages/worker/src/api/routes/glo…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hr66-5mqr-8mpx</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2483 — Budibase: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2483</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Budibase ausnutzen, um erweiterte Berechtigungen zu erlangen, SQL-Injection durchzuführen, Sicherheitsmaßnahmen zu umgehen, Konten zu übernehmen, Daten zu manipulieren oder offenzulegen sowie einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Budibase ausnutzen, um erweiterte Berechtigungen zu erlangen, SQL-Injection durchzuführen, Sicherheitsmaßnahmen zu umgehen, Konten zu übernehmen, Daten zu manipulieren oder offenzulegen sowie einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2483</guid>
    </item>
  </channel>
</rss>
