A vulnerability was found in Budibase up to 3.39.24. It has been rated as problematic. This issue affects some unknown processing of the file packages/worker/src/api/routes/global/groups.ts of the component Global Groups Endpoint. Performing a manipulation results in improper privilege management.
This vulnerability is identified as CVE-2026-73301. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.