OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-100685 (CVSS 8.3)

NVD · officialPublished Sep 26, 2026Risk 37/100

Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowing builders to enumerate chat identity link records across all workspaces in a tenant. Attackers with builder access to a single workspace can retrieve sensitive chat identity linking data including user IDs and external chat service identifiers from other workspaces they have no permission to access.

CVSS
8.3
AV:NetworkAC:LowPR:LowUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source