Budibase Server versions before 3.41.3 contain a server-side request forgery (SSRF) vulnerability in the datasource verify endpoint. The flaw allows builder-level authenticated users to supply arbitrary URLs without any SSRF validation in place. Attackers can exploit this vulnerability by directing requests to attacker-controlled servers, enabling them to intercept internal CouchDB credentials. Successful exploitation can grant attackers full database access, particularly impacting cloud deployments of Budibase. The vulnerability is tracked as CVE-2026-82243 and has been patched in version 3.41.3. Security advisories have been published by both GitHub and VulnCheck detailing the issue and its impact.