A vulnerability classified as critical was found in Budibase up to 3.39.x . Affected by this vulnerability is an unknown functionality of the file /api/global/users/tenant/owner . The manipulation results in improper authorization. This vulnerability was named CVE-2026-72856 . The attack may be performed from remote. There is no available exploit. Upgrading the affected component is advised.