← Terug naar overzicht

Budibase Server versions before 3.41.3 contain a server-side request forgery (SSRF) vulnerability in the datasource verify endpoint. The flaw allows builder-level authenticated users to supply arbitrary URLs without any SSRF validation in place. Attackers can exploit this vulnerability by directing requests to attacker-controlled servers, enabling them to intercept internal CouchDB credentials. Successful exploitation can grant attackers full database access, particularly impacting cloud deployments of Budibase. The vulnerability is tracked as CVE-2026-82243 and has been patched in version 3.41.3. Security advisories have been published by both GitHub and VulnCheck detailing the issue and its impact.

Affected products

  • Budibase Server

Related CVE's

  • CVE-2026-82243

Categories

  • Cloud & Virtualization
  • Database & Storage
  • Identity & Access
  • Web Technologies