What is CVE-2026-72855?
Budibase versions before 3.40.0 contain a server-side request forgery (SSRF) vulnerability in OpenAPI query import and REST query execution that allows authenticated builder-level users to bypass DNS pinning protections via DNS rebinding attacks. Users should upgrade to version 3.40.0 or later to mitigate the risk.
Azərbaycanca: Budibase platformasının 3.40.0-dan əvvəlki versiyalarında autentifikasiya olunmuş builder səviyyəli istifadəçilər üçün server-side request forgery (SSRF) zəifliyi mövcuddur. Bu boşluq OpenAPI query import və REST query icrası zamanı DNS rebinding hücumları vasitəsilə DNS pinning qorunmasını keçməyə imkan verir. Təhlükəsizlik üçün Budibase-i ən az 3.40.0 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918; shared vendor: Budibase
FAQ2
Which versions of the Budibase platform does CVE-2026-72855 affect?
This vulnerability affects Budibase platform versions before 3.40.0.
What attack type is used to bypass DNS pinning protections through this SSRF vulnerability?
This vulnerability allows bypassing DNS pinning protections via DNS rebinding attacks.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.