Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 30 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 26 Sep 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Budibase
Budibase server |
|
| Vendors & Products |
Budibase
Budibase server |
Sat, 26 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowing builders to enumerate chat identity link records across all workspaces in a tenant. Attackers with builder access to a single workspace can retrieve sensitive chat identity linking data including user IDs and external chat service identifiers from other workspaces they have no permission to access. | |
| Title | Budibase before 3.45.0 Information Disclosure via Chat Links | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-30T17:09:00.076Z
Reserved: 2026-09-26T02:36:51.810Z
Link: CVE-2026-100685
Updated: 2026-09-30T17:08:37.375Z
Status : Deferred
Published: 2026-09-26T14:16:52.860
Modified: 2026-09-30T18:18:01.477
Link: CVE-2026-100685
No data.
OpenCVE Enrichment
Updated: 2026-09-26T17:00:14Z
-
CWE-863
Incorrect Authorization