CVE Explorer
CVE-2026-45718
Budibase is an open-source low-code platform. Prior to 3.38.1, the row action trigger endpoint (POST /api/tables/:sourceId/actions/:actionId/trigger) fails to validate that the user-supplied rowId is within the scope of the view's row filters. A user with access to a filtered view can trigger row actions on any row in the underlying table, including rows explicitly excluded by the view's security filters. This vulnerability is fixed in 3.38.1.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"budibase","vendor":"Budibase","versions":[{"status":"affected","version":"< 3.38.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:477bf56f599ca36d14f964ed35a3588144f8e5c65fae437444acc983919a9ef0 · sha256:703fc2fa788a500b… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:477bf56f599ca36d14f964ed35a3588144f8e5c65fae437444acc983919a9ef0 · sha256:703fc2fa788a500b… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-863","description":"CWE-863: Incorrect Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:477bf56f599ca36d14f964ed35a3588144f8e5c65fae437444acc983919a9ef0 · sha256:703fc2fa788a500b… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/Budibase/budibase/releases/tag/3.38.1","tags":["x_refsource_MISC"],"url":"https://github.com/Budibase/budibase/releases/tag/3.38.1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:477bf56f599ca36d14f964ed35a3588144f8e5c65fae437444acc983919a9ef0 · sha256:703fc2fa788a500b… · /containers/cna/references/1
{"tags":["exploit"],"url":"https://github.com/Budibase/budibase/security/advisories/GHSA-3263-v5v9-xq8q"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:477bf56f599ca36d14f964ed35a3588144f8e5c65fae437444acc983919a9ef0 · sha256:703fc2fa788a500b… · /containers/adp/0/references/0
{"name":"https://github.com/Budibase/budibase/security/advisories/GHSA-3263-v5v9-xq8q","tags":["x_refsource_CONFIRM"],"url":"https://github.com/Budibase/budibase/security/advisories/GHSA-3263-v5v9-xq8q"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:477bf56f599ca36d14f964ed35a3588144f8e5c65fae437444acc983919a9ef0 · sha256:703fc2fa788a500b… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.