CVEFinder.io

CVE-2026-73406

⚠️ high
🔍 Scan for this CVE
Summary

Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/users/tenant/:id was listed in PUBLIC_ENDPOINTS in packages/worker/src/api/index.ts, and tenantUserLookup returned a full PlatformUser document. An unauthenticated caller could query an email or user identifier, distinguish existing users from missing users, and obtain tenant identifiers, user identifiers, email addresses, SSO identifiers, and document revision metadata. This issue is fixed in version 3.39.32.

CVSS Score
7.5
High
EPSS Score
-
Published Date
2026-08-12
First Seen: 2026-08-13
📊 Relative Risk Intelligence

This CVE is Moderate Risk - more severe than 68.2% of all 344,170 vulnerabilities in our database.

#109,511
Above average severity
Severity Percentile
Last Modified 2026-08-12
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE IDs (Weakness Types)

📦 Affected Products 0

No affected products information available

🔗 References 4