Cyber Resilience

CVE-2026-42239

HighPublic PoCUpdated

Published: 07 May 2026

Published
07 May 2026
Modified
04 June 2026
KEV Added
Patch
CVSS Score v3.1 8.1 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N
EPSS Score 0.0028 20.2th percentile
Risk Priority 55 floored blend · peak EPSS

Summary

CVE-2026-42239 is a high-severity Sensitive Cookie Without 'HttpOnly' Flag (CWE-1004) vulnerability in Budibase Budibase. Its CVSS base score is 8.1 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique Steal Web Session Cookie (T1539); ranked at the 20.2th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

OWASP Top 10 for Web (2025)

EU & UK References

Vulnerability details

Budibase is an open-source low-code platform. Prior to version 3.35.10, the budibase:auth cookie containing the JWT session token is set with httpOnly: false at packages/backend-core/src/utils/utils.ts:218. JavaScript can read this cookie via document.cookie. This means every XSS becomes a full account…

more

takeover — the attacker steals the JWT and has persistent access to the victim's account. The cookie also lacks secure: true (sent over plaintext HTTP) and sameSite attribute. This issue has been patched in version 3.35.10.

CWE(s)

Related Threats

MITRE ATT&CK Enterprise TechniquesAI

T1539 Steal Web Session Cookie Credential Access
An adversary may steal web application or service session cookies and use them to gain access to web applications or Internet services as an authenticated user without needing credentials.
T1078 Valid Accounts Stealth
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
Why these techniques?

Missing httpOnly on JWT auth cookie directly enables JS-based theft of web session cookies (T1539) via any XSS, resulting in persistent use of stolen valid accounts (T1078).

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

CVEs Like This One

CVE-2026-35218Same product: Budibase Budibase
CVE-2026-25040Same product: Budibase Budibase
CVE-2026-41428Same product: Budibase Budibase
CVE-2026-25045Same product: Budibase Budibase
CVE-2026-25041Same product: Budibase Budibase
CVE-2026-30240Same product: Budibase Budibase
CVE-2026-35214Same product: Budibase Budibase
CVE-2026-33226Same product: Budibase Budibase
CVE-2026-31818Same product: Budibase Budibase
CVE-2026-31816Same product: Budibase Budibase

Affected Assets

budibase
budibase
≤ 3.35.10

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References