Skip to content

Base44 · 2025-01

Base44 authentication flaw

A platform-wide authentication flaw allowed access to private enterprise data.

Last updated 2025-01
Not verified

What the sources report

The sources report a platform-wide authentication flaw.

It allowed access to private enterprise data.

Root cause class

Broken authentication

Covered by

What ShipReady can say

Sign in behaviour is inside the app. A check from outside cannot exercise it, so auth flows stay Not verified until a Launch Review tests them.

Sources

Check your app

Run all sixteen groups on your published address and see the evidence behind every result.

Running it confirms you own this app or are authorized to test it. ShipReady reads its public pages and JavaScript bundles.

ShipReady is not a penetration test or a security certification. No automated check can prove an application is secure.

Last updated September 20, 2026