Sploitus

CVE-2026-72849

No indexed exploits for CVE-2026-72849 yet

Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff endpoint that allows attackers to bind an external chat identity to a victim's account. Attackers can craft a phishing page that auto-submits a POST request with a leaked confirmation token to bind their chat identity to a victim user's account, enabling impersonation within agent operations and inheritance of victim permissions.

Affected products
Budibase
Fix
Available
CVSS 4.0
8.7 HIGH
CVSS 3.1
7.7 HIGH
EPSS
0.1% (3th percentile)
Weakness
CWE-352
NVD status
Received
Published
2026-08-13
CVE-2026-72849 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-72849 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-72849 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.