What is CVE-2026-72857?
CVE-2026-72857 is a vulnerability in Budibase before version 3.40.0 where datasource credentials stored in STRING typed fields are not redacted, exposing plaintext MongoDB connection strings and Firebase private keys to authenticated users. Users with table read permissions can retrieve these credentials via the read API, necessitating an immediate update to version 3.40.0 or later and restricting table read permissions.
Azərbaycanca: CVE-2026-72857, Budibase platformasının 3.40.0 versiyasından əvvəlki versiyalarında STRING tipli sahələrdə saxlanılan verilənlər mənbəyi etimadnamələrinin maskalanmaması zəifliyidir. Bu, autentifikasiya olunmuş istifadəçilərə MongoDB bağlantı sətirləri və Firebase özəl açarlarını açıq mətn şəklində oxumağa imkan verir. İstifadəçilər dərhal 3.40.0 və ya daha yuxarı versiyaya yeniləməli və cədvəl oxuma icazələrini məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-200; shared vendor: Budibase
FAQ2
Which versions of Budibase are affected by CVE-2026-72857?
This vulnerability affects Budibase versions before 3.40.0.
What sensitive information can authenticated users obtain through CVE-2026-72857?
Authenticated users can retrieve MongoDB connection strings and Firebase private keys in plaintext.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.