A vulnerability, which was classified as critical , was found in Budibase up to 3.39.23 . Impacted is the function validateGlobalRoleUpdate of the file packages/server/src/api/controllers/public/globalRoleValidation.ts of the component Global Role Validation . Executing a manipulation can lead to improper privilege management. The identification of this vulnerability is CVE-2026-73305 . The attack may be launched remotely. There is no exploit available. You should upgrade the affected component.