云虫漏洞情报

CVE-2026-82242 - Budibase versions before 3.41.3 contain a missing authorization vulnerability in the POST /api/resources/duplicate endpoint that allows authenticated builders to inject tables, automations, queries, and screens into any other application without holding any role in the destination workspace. Attackers can inject resources by specifying an arbitrary destination workspace ID in the request body, then trigger injected automations with outgoing webhooks to exfiltrate data from victi - 漏洞详情

漏洞编号:CVE-2026-82242

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-82242

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-862

发布/更新时间:2026-08-28 / 2026-08-28

漏洞描述

Budibase versions before 3.41.3 contain a missing authorization vulnerability in the POST /api/resources/duplicate endpoint that allows authenticated builders to inject tables, automations, queries, and screens into any other application without holding any role in the destination workspace. Attackers can inject resources by specifying an arbitrary destination workspace ID in the request body, then trigger injected automations with outgoing webhooks to exfiltrate data from victim applications.

相关链接

相关漏洞

« 返回首页