A vulnerability classified as critical was found in Budibase up to 3.39.x. Affected by this vulnerability is an unknown functionality of the file /api/global/users/tenant/owner. The manipulation results in improper authorization.
This vulnerability was named CVE-2026-72856. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.