# sonatype-2026-005076

@budibase/server - Incorrect Authorization

Published Jul 25, 2026

[Advisory · GHSA-xcx6-4f2g-hhgx](https://github.com/advisories/GHSA-xcx6-4f2g-hhgx)

**CVSS Score**: High 7.7

## Security Details

### Components Impacted
- Sonatype Research

### sonatype-2026-005076 Security Details

**CVE ID**: sonatype-2026-005076  
**CVE Description**: @budibase/server - Incorrect Authorization  
**Published**: Jul 25, 2026  
**CVSS Score & Severity**: 7.7 High  
**CVSS Vector**: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N  
**EPSS Score**: 0%  
**Malware**: malware  
**KEV Status**: Not in KEV Catalog: No known exploits

### Affected Ecosystems
- Source: Sonatype

### References
- [GitHub · Advisory · GHSA-xcx6-4f2g-hhgx](https://github.com/advisories/GHSA-xcx6-4f2g-hhgx)
