{"id":"CVE-2026-100688","published":"2026-09-26T14:16:53.280","lastModified":"2026-09-28T17:17:45.237","description":"Budibase server before 3.45.0 contains a cross-tenant information disclosure vulnerability in the GET /api/applications/:appId/appPackage endpoint that allows authenticated users to read another tenant's application metadata and source code. Attackers can supply a victim tenant's app id to retrieve sensitive application details including navigation structure, role names, internal screen URLs, JavaScript snippets, and user identifiers without authorization checks.","cvssScore":6.5,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwes":["CWE-639"],"vendors":[],"products":[],"references":[{"url":"https://github.com/Budibase/budibase/security/advisories/GHSA-4946-qf2m-wrh5","tags":[]},{"url":"https://www.vulncheck.com/advisories/budibase-server-before-3.45.0-cross-tenant-information-disclosure","tags":[]},{"url":"https://github.com/Budibase/budibase/security/advisories/GHSA-4946-qf2m-wrh5","tags":[]}],"exploitRefs":[{"url":"https://github.com/Budibase/budibase/security/advisories/GHSA-4946-qf2m-wrh5","tags":[]},{"url":"https://github.com/Budibase/budibase/security/advisories/GHSA-4946-qf2m-wrh5","tags":[]}],"hasPoc":true,"ai":null}