# sonatype-2026-005081

@budibase/server - Improper Privilege Management

Published Jul 25, 2026

[Advisory · GHSA-j9fc-w3mr-x6mv](https://github.com/advisories/GHSA-j9fc-w3mr-x6mv)

## Security Details

### Components Impacted

- Sonatype Research

### sonatype-2026-005081 Security Details

- **CVE ID**: sonatype-2026-005081  
- **CVE Description**: @budibase/server - Improper Privilege Management  
- **Published**: Jul 25, 2026  
- **CVSS Score & Severity**: 8.8 High  
- **CVSS Vector**: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H  
- **EPSS Score**: 0%  
- **KEV Status**: Not in KEV Catalog: No known exploits  
- **Affected Ecosystems**: Affected  
- **Source**: Sonatype

### References

- [GitHub · Advisory · GHSA-j9fc-w3mr-x6mv](https://github.com/advisories/GHSA-j9fc-w3mr-x6mv "https://github.com/advisories/GHSA-j9fc-w3mr-x6mv")
