CVE-2026-25737 | budibase up to 3.24.0 client-side enforcement of server-side security (GHSA-2hfr-343j-863r)
A vulnerability classified as critical was found in budibase up to 3.24.0. Impacted is an unknown function. The manipulation results in client-side enforcement of server-side security.
This vulnerability is known as CVE-2026-25737. It is possible to launch the attack remotely. No exploit is available.