What is CVE-2026-67311?
A Server-Side Request Forgery (SSRF) vulnerability exists in Budibase versions before 3.38.1 within the REST datasource integration, which fails to validate HTTP redirects against the IP blacklist. Attackers with the Builder role can exploit this by configuring a REST datasource that redirects to internal network resources. Users should upgrade to version 3.38.1 or later immediately.
Azərbaycanca: Budibase platformasının 3.38.1-dən əvvəlki versiyalarında REST məlumat mənbəyi inteqrasiyasında Server-Side Request Forgery (SSRF) zəifliyi aşkarlanıb. Bu boşluq Builder roluna malik hücumçulara REST sorğuları vasitəsilə daxili şəbəkə resurslarına icazəsiz giriş əldə etməyə imkan verir. İstifadəçilərə dərhal 3.38.1 və ya daha yuxarı versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918; shared vendor: Budibase
FAQ2
What role does an attacker need to exploit CVE-2026-67311?
The attacker needs to have the Builder role in the Budibase platform.
What should Budibase users do to protect against CVE-2026-67311?
Users should immediately upgrade Budibase to version 3.38.1 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.