A vulnerability classified as critical was found in Budibase up to 3.39.x. Affected by this vulnerability is an unknown functionality of the file /api/global/users/tenant/owner. The manipulation results in improper authorization.

This vulnerability was named CVE-2026-72856. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is advised.