budibase server
17 known vulnerabilities in budibase server, 2 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-100688 CVSS 7.1 high Budibase server before 3.45.0 contains a cross-tenant information disclosure vulnerability in the GET /api/applications/:appId/appPackage…
- CVE-2026-100687 CVSS 7.0 high Budibase Server before 3.45.0 fails to redact plaintext datasource credentials before broadcasting external table updates to the Builder…
- CVE-2026-100686 CVSS 8.6 high Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endpoint, allowing…
- CVE-2026-100685 CVSS 8.3 high Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowing builders to enumerate chat identity…
- CVE-2026-100684 CVSS 9.2 critical Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server. In…
- CVE-2026-100683 CVSS 8.9 high Budibase (@budibase/server) before 3.45.0 builds MySQL and MSSQL column-rename DDL in packages/backend-core/src/sql/sqlTable.ts by…
- CVE-2026-100682 CVSS 8.7 high Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon upload endpoint that extracts user-supplied…
- CVE-2026-100681 CVSS 6.3 medium Budibase before 3.45.0 contains an unauthenticated server-side request forgery and credential exfiltration vulnerability in the Microsoft…
- CVE-2026-100680 CVSS 8.6 high Budibase versions before 3.45.0 fail to disable external JSON reference resolution in the OpenAPI/Swagger import validator, allowing…
- CVE-2026-82246 CVSS 7.1 high Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the query import endpoint that fails to validate…
- CVE-2026-82245 CVSS 7.2 high Budibase before 3.41.3 fails to enforce role-based authorization on license management endpoints, allowing any authenticated user to…
- CVE-2026-82244 CVSS 9.4 critical Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling that allows authenticated admin users to…
- CVE-2026-82243 CVSS 8.3 high Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the datasource verify endpoint that allows…
- CVE-2026-82242 CVSS 8.3 high Budibase versions before 3.41.3 contain a missing authorization vulnerability in the POST /api/resources/duplicate endpoint that allows…
- CVE-2026-82241 CVSS 7.1 high Budibase backend-core (@budibase/backend-core, as used by @budibase/server) omits the shared address space range 100.64.0.0/10 from its…
- CVE-2026-82240 CVSS 8.6 high Budibase before 3.41.3 fails to validate app-scoped builder role assignments in the public user create and update endpoints, allowing an…
- CVE-2026-82239 CVSS 8.6 high Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/query endpoint, allowing low-privilege…