{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-81335/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-81335"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Baserow"],"_cs_severities":["high"],"_cs_tags":["web-application-vulnerability","access-control-bypass","cve-2026-81335"],"_cs_type":"advisory","_cs_vendors":["Baserow"],"content_html":"\u003cp\u003eBaserow version 2.3.0 and earlier contain a critical authorization vulnerability (CVE-2026-81335) within the Application Builder component. The issue stems from the dispatch and record-name views in \u003ccode\u003ebackend/src/baserow/contrib/builder/api/data_sources/views.py\u003c/code\u003e, which are configured with permission classes that do not restrict access to authenticated users. Furthermore, the \u003ccode\u003eDataSourceService.dispatch_data_sources\u003c/code\u003e function in \u003ccode\u003ebackend/src/baserow/contrib/builder/data_sources/service.py\u003c/code\u003e fails to enforce the results of internal permission checks.\u003c/p\u003e\n\u003cp\u003eBecause the system continues execution regardless of the check result and uses the integration's internal credentials for the data source dispatch, an unauthenticated attacker can retrieve sensitive row and field information. Given that data source identifiers are small, sequential integers, an attacker can trivially enumerate these resources to exfiltrate data from multiple application builders within a target instance. This vulnerability was addressed in version 2.3.1.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to bypass access controls and perform unauthorized data retrieval. By enumerating predictable integer IDs, an attacker can exfiltrate sensitive information from any data source accessible to the integration's internal service account. The impact includes potential large-scale data breach of application builder contents.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of Baserow to version 2.3.1 or higher immediately to apply the fix for CVE-2026-81335.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for anomalous, high-frequency GET or POST requests directed at \u003ccode\u003e/api/builder/data-sources/\u003c/code\u003e or \u003ccode\u003e/api/builder/data-sources/record-name/\u003c/code\u003e endpoints.\u003c/li\u003e\n\u003cli\u003eMonitor for requests involving sequential integer IDs in URL parameters or request bodies as indicators of resource enumeration.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-27T19:10:33Z","date_published":"2026-08-27T19:10:33Z","id":"https://feed.craftedsignal.io/briefs/2026-08-baserow-auth-bypass/","summary":"A vulnerability in Baserow's Application Builder allows unauthenticated attackers to bypass permission checks and retrieve sensitive data by leveraging improperly handled access control logic.","title":"Unauthenticated Data Source Access in Baserow Application Builder","url":"https://feed.craftedsignal.io/briefs/2026-08-baserow-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-81335","version":"https://jsonfeed.org/version/1.1"}