CVE-2026-73406
⚠️ highSummary
Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/users/tenant/:id was listed in PUBLIC_ENDPOINTS in packages/worker/src/api/index.ts, and tenantUserLookup returned a full PlatformUser document. An unauthenticated caller could query an email or user identifier, distinguish existing users from missing users, and obtain tenant identifiers, user identifiers, email addresses, SSO identifiers, and document revision metadata. This issue is fixed in version 3.39.32.
CVSS Score
7.5
High
EPSS Score
-
Published Date
2026-08-12
First Seen: 2026-08-13
📊 Relative Risk Intelligence
This CVE is Moderate Risk - more severe than 68.2% of all 344,170 vulnerabilities in our database.
#109,511
Above average severity
Severity Percentile
Last Modified
2026-08-12
Source
NVD 🔗
CVSS Vector 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE IDs (Weakness Types)