A vulnerability, which was classified as critical, has been found in Budibase up to 3.39.24. Affected by this vulnerability is an unknown functionality of the file packages/server/src/api/controllers/automation.ts of the component Automation. This manipulation causes improper privilege management.
This vulnerability is tracked as CVE-2026-73308. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.