# sonatype-2026-005069

@budibase/server - Improper Authentication

Published Jul 25, 2026

[Advisory · GHSA-hp6v-6jw7-gv2f](https://github.com/advisories/GHSA-hp6v-6jw7-gv2f)

CVSS Score Critical

9.0

## Security Details

### Components Impacted

- **Source**: Sonatype  
- **CVE ID**: sonatype-2026-005069  
- **CVE Description**: @budibase/server - Improper Authentication  
- **Published**: Jul 25, 2026  
- **CVSS Score & Severity**: 9.0 Critical  
- **CVSS Vector**: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H  
- **EPSS Score**: 0%  
- **Malware**: malware  
- **KEV Status**: Not in KEV Catalog: No known exploits

### Affected Ecosystems

- **Source**: Sonatype

### References

- [GitHub · Advisory · GHSA-hp6v-6jw7-gv2f](https://github.com/advisories/GHSA-hp6v-6jw7-gv2f "https://github.com/advisories/GHSA-hp6v-6jw7-gv2f")
