# sonatype-2026-005072

@budibase/server - Missing Authorization

Published Jul 25, 2026

[Advisory · GHSA-4qcj-m5wp-jmf4](https://github.com/advisories/GHSA-4qcj-m5wp-jmf4)

CVSS Score Medium 4.3

## Security Details

### Components Impacted

Sonatype Research

### sonatype-2026-005072 Security Details

CVE ID sonatype-2026-005072

CVE Description @budibase/server - Missing Authorization

Published Jul 25, 2026

CVSS Score & Severity

4.3 Medium

CVSS Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

EPSS Score 0%

**Malware**: malware

**KEV Status**: Not in KEV Catalog: No known exploits

### Affected Ecosystems

Source Sonatype

### References

[GitHub · Advisory · GHSA-4qcj-m5wp-jmf4](https://github.com/advisories/GHSA-4qcj-m5wp-jmf4 "https://github.com/advisories/GHSA-4qcj-m5wp-jmf4")
