CVE-2026-46424
📛 CVE Title
(no title)
Description
Budibase: Missing Cache Invalidation on Public API Role Unassignment Allows Revoked Users to Retain Privileges for Up to 1 Hour
Overview
- State
- —
- Assigner (CNA)
- —
- CVSS severity
- medium
- CVSS score
- 4.2 / 10
- CVSS vector
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N- Effective score
- 4.2 / 10 MEDIUM source: CNA overview
- CWE(s)
- —
- Reserved
- —
- Published
- —
- Last updated
- —
- Source
- https://www.tenable.com/cve/CVE-2026-46424
NVD / KEV / EPSS data refreshed 2026-05-25 00:14 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-32597 - Assigner
- GitHub_M
- Published
- May 27, 2026, 5:05:21 PM
- Updated
- May 28, 2026, 2:08:42 PM
- EUVD base score (CVSS 3.1)
-
4.2 / 10
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N - EUVD-reported EPSS
- 0.1600
- Vendors
- budibase
- Products
-
budibase (< 3.38.2)
- Aliases
-
GHSA-6vp2-6r7m-2jvx
ENISA description: Budibase is an open-source low-code platform. Prior to 3.38.2, the public API role unassignment endpoint (POST /api/public/v1/roles/unassign) updates user documents in CouchDB but does not invalidate the corresponding Redis user cache entries. Because the authentication middleware resolves user identity and permissions from this cache (TTL: 3600 seconds), a user whose admin, builder, or app-level roles have been revoked via the public API retains those privileges for up to 1 hour. This vulnerability is fixed in 3.38.2.
Vendor references (0)
References embedded in the original CVE record by the assigning CNA.
None in the CVE record.
Web references (5)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://github.com/Budibase/budibase/releases/tag/3.38.2 tenable:github.com
- https://github.com/Budibase/budibase/security/advisories/GHSA-6vp2-6r7m-2jvx tenable:github.com
- https://www.first.org/epss/ tenable:www.first.org
- https://nvd.nist.gov/vuln/detail/CVE-2026-46424 tenable:nvd.nist.gov
- https://www.cve.org/CVERecord?id=CVE-2026-46424 tenable:www.cve.org
Remediations (10)
-
web:blog.qualys.com
Starting the year on a security-first note, Microsoft's January 2026 Patch Tuesday resolves several vulnerabilities that could impact enterprise environments. Here's a quick breakdown of what you need…
2026-05-26 03:08 UTC -
web:krebsonsecurity.com
For a clickable, per- patch breakdown, check out the SANS Internet Storm Center Patch Tuesday roundup. Running into problems applying any of these updates?
2026-05-26 03:08 UTC -
web:thecyberexpress.com
Microsoft's Patch Tuesday April 2026 release has introduced one of the most extensive security update rollouts of the year, addressing a total of 167 vulnerabilities across Windows operating systems and associated software. This latest Microsoft Patch Tuesday also includes fixes for two zero-day ...
2026-05-26 03:08 UTC -
web:thewincentral.com
April 2026 Windows update causes LSASS crashes and reboot loops on domain controllers. Microsoft is working on a fix . - Read in Latest News on WinCentral
2026-05-26 03:08 UTC -
web:threatprotect.qualys.com
Zero-day Vulnerabilities Patched in April Patch Tuesday Edition CVE - 2026 -33825: Microsoft Defender Elevation of Privilege Vulnerability Microsoft Defender is a comprehensive, AI-powered security suite that provides malware protection, phishing detection, and web protection for individuals and businesses.
2026-05-26 03:08 UTC -
web:www.bleepingcomputer.com
Today is Microsoft's April 2026 Patch Tuesday with security updates for 167 flaws, including 2 zero-day vulnerabilities.
2026-05-26 03:08 UTC -
web:www.crowdstrike.com
Microsoft's April 2026 Patch Tuesday addresses 164 CVEs , featuring 8 Critical vulnerabilities, one exploited zero-day, and one disclosed zero-day.
2026-05-26 03:08 UTC -
web:www.lansweeper.com
Which vulnerabilities, issues, and other things did Microsoft update? Discover what's new using Lansweeper's Patch Tuesday May 2026 summary.
2026-05-26 03:08 UTC -
web:www.techrepublic.com
Microsoft's April 2026 Patch Tuesday fixes 165 vulnerabilities, including two zero-days, in one of the company's largest monthly security updates.
2026-05-26 03:08 UTC -
web:zecurit.com
Get the complete breakdown of Microsoft's May 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .
2026-05-26 03:08 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.