← Back to overview

Budibase Server versions before 3.41.3 contain a server-side request forgery (SSRF) vulnerability in the datasource verify endpoint. Builder-level users can supply arbitrary URLs without any SSRF validation, allowing them to direct requests to attacker-controlled servers. This flaw enables attackers to leak internal CouchDB credentials used by Budibase in cloud deployments. Successful exploitation grants full database access, posing a severe risk to cloud-hosted Budibase instances. The vulnerability is particularly dangerous because it requires only builder-level privileges, which may be accessible to a broader set of users. Organizations running Budibase in cloud environments should upgrade to version 3.41.3 or later immediately. No workaround is described beyond patching.

Affected products

  • Budibase Server

Related CVE's

  • CVE-2026-82243

Categories

  • Cloud & Virtualization
  • Data Breach & Exfiltration
  • Database & Storage
  • Web Technologies