Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 14 Aug 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Budibase server
|
|
| Vendors & Products |
Budibase server
|
Thu, 13 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff endpoint that allows attackers to bind an external chat identity to a victim's account. Attackers can craft a phishing page that auto-submits a POST request with a leaked confirmation token to bind their chat identity to a victim user's account, enabling impersonation within agent operations and inheritance of victim permissions. | |
| Title | Budibase before 3.40.0 Identity Confusion via Chat-Link Handoff CSRF | |
| First Time appeared |
Budibase
Budibase budibase |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:budibase:budibase:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Budibase
Budibase budibase |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-13T21:54:41.963Z
Reserved: 2026-08-10T15:14:51.468Z
Link: CVE-2026-72849
No data.
Status : Received
Published: 2026-08-13T22:17:24.140
Modified: 2026-08-13T22:17:24.140
Link: CVE-2026-72849
No data.
OpenCVE Enrichment
Updated: 2026-08-14T09:30:14Z