External risk intelligence

Budibase OIDC/SSO Authentication Bypass Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2026-100684

Budibase is a low-code platform commonly deployed as a web application accessible over the internet to allow remote team collaboration, app development, and management. Authentication portals and SSO login paths in such applications are typically exposed to the public internet to facilitate user access.

Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses an authentication bypass vulnerability in Budibase, a low-code platform. Attackers could exploit this by registering with a trusted identity provider and asserting a victim's invited email address to claim pending invitations, potentially leading to full tenant compromise, including access to sensitive data and administrative privileges.

  • An attacker can bypass login to gain unauthorized access.
  • This vulnerability could lead to full system compromise.
  • Confirm if your Budibase instance is affected and needs attention.

Attack Path

How an attacker could exploit the issue

An attacker could impersonate an invited user by registering with a trusted identity provider and asserting the victim's email address during the OIDC/SSO login process. This bypasses the need for a valid invite code or verified email, allowing the attacker to claim the pending invitation and gain the privileges associated with it, potentially leading to full tenant compromise.

  • Attacker registers with trusted identity provider.
  • Bypasses invite code and email verification.
  • Full tenant compromise, including admin access.

Live Threat

Current exploitation, exposure, and threat context

An attacker could gain unauthorized access to a Budibase tenant by exploiting an authentication bypass in the OIDC/SSO login. This could occur when a user is invited to a tenant, and the attacker registers with an identity provider (IdP) trusted by the tenant, then asserts the invited user's email address. This allows the attacker to claim the pending invite and gain the privileges of the invited user, potentially leading to full tenant compromise.

  • Invited user accounts and tenant access.
  • Attacker registers with a trusted IdP.
  • Full tenant compromise and access.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Budibase platform, particularly its authentication and SSO features, falls under the purview of the application owners and potentially the platform or infrastructure teams responsible for its deployment. The first actionable step is to identify all Budibase instances, determine their exposure and criticality, and locate the accountable owner before planning remediation.

  • Identify Budibase instances and accountable owners.
  • Verify SSO and invite functionality exposure.
  • Plan remediation considering tenant impact.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Budibase and what do people use it for?

Budibase is a low-code platform designed to help teams rapidly build, automate, and manage custom internal business applications. It provides a web-based interface where users can create data-driven tools and connect to various data sources, allowing for streamlined collaboration and task management within an organization.

What is the weakness class for CVE-2026-100684?

This vulnerability is classified as CWE-287, or Improper Authentication. In plain terms, it means the application fails to correctly verify the identity of a user during the OIDC/SSO login process. Instead of ensuring the user legitimately owns the invitation they are claiming, the system blindly trusts an email address provided by an external identity provider, allowing attackers to bypass critical access gates.

How does an attacker trigger this authentication bypass?

The bypass occurs when an attacker registers an account with an identity provider that a Budibase tenant trusts. By providing the email address of a legitimate, pending invitee, the attacker tricks the Budibase server into assigning that invite's privileges to them. Crucially, the system does not trigger this bug if there is no pending invitation for that email address, as the flaw specifically relies on hijacking existing, unaccepted invites.

Is my Budibase instance at risk?

According to Halo Surface Signal, Budibase instances are frequently deployed as internet-facing applications to support remote collaboration. If your instance is accessible over the public internet and uses OIDC or SSO for authentication, it is likely exposed to this threat. You should prioritize assessment if your setup allows external users to join via third-party identity providers.

What steps should I take if I run Budibase?

Start by identifying all deployed Budibase instances within your environment and confirming their specific version numbers. Since this issue involves the @budibase/server component, verify if your platform is running a version between 3.41.0 and 3.45.0. Once identified, coordinate with the application owners to understand the potential impact on your users and plan for the necessary software updates to secure your authentication path.

References