{"id":"CVE-2026-100685","published":"2026-09-26T14:16:52.860","lastModified":"2026-09-28T16:36:05.010","description":"Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowing builders to enumerate chat identity link records across all workspaces in a tenant. Attackers with builder access to a single workspace can retrieve sensitive chat identity linking data including user IDs and external chat service identifiers from other workspaces they have no permission to access.","cvssScore":7.7,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","cwes":["CWE-863"],"vendors":[],"products":[],"references":[{"url":"https://github.com/Budibase/budibase/security/advisories/GHSA-76m3-47v8-p7h6","tags":[]},{"url":"https://www.vulncheck.com/advisories/budibase-before-3.45.0-information-disclosure-via-chat-links","tags":[]}],"exploitRefs":[{"url":"https://github.com/Budibase/budibase/security/advisories/GHSA-76m3-47v8-p7h6","tags":[]}],"hasPoc":true,"ai":null}