A vulnerability identified as problematic has been detected in Budibase up to 3.39.24 . This impacts an unknown function of the file packages/server/src/utilities/global.ts of the component User Object Processing . Performing a manipulation of the argument oauth2.accessToken/oauth2.refreshToken results in improper privilege management. This vulnerability is reported as CVE-2026-73304 . The attack is possible to be carried out remotely. No exploit exists. You should upgrade the affected component