Budibase vulnerabilities
17 CVEs tracked
Budibase appears in our recent reports with multiple critical vulnerabilities across several versions, requiring urgent patching attention. Key risks include an unauthenticated SQL injection (CVE-2026-72851), a server-side request forgery (SSRF) bypassing IP blacklists (CVE-2026-67311), and MongoDB NoSQL injection flaws (CVE-2026-73617, CVE-2026-73618). Additionally, privilege escalation issues allow lower-privileged users to manipulate role assignments or enumerate groups (CVE-2026-73305, CVE-2026-73301), while plaintext exposure of datasource credentials (CVE-2026-72857) poses a confidentiality risk. Defenders should immediately upgrade to version 3.40.0 or later and enhance monitoring for injection attacks, particularly those targeting webhook-triggered automations.
Azərbaycanca: Budibase son hesabatlarımızda kritik boşluqlarla bağlı önə çıxır və bir neçə versiyada təcili yeniləmə tələb edən zəifliklər qeydə alınıb. Əsas risklər autentifikasiya olunmamış SQL injection (CVE-2026-72851), xarici server sorğusu saxtakarlığı (SSRF) (CVE-2026-67311) və MongoDB NoSQL injection (CVE-2026-73617, CVE-2026-73618) zəifliklərini əhatə edir. Bundan əlavə, aşağı imtiyazlı istifadəçilərin rolları genişləndirməsi (CVE-2026-73305, CVE-2026-73301) və həssas datasource etimadnamələrinin açıq mətndə oxunması (CVE-2026-72857) kimi icazə problemləri mövcuddur. Müdafiəçilər dərhal 3.40.0 və ya daha yuxarı versiyalara yüksəltməli, xüsusilə webhook avtomatlaşdırmalarına yönələn injection hücumlarına qarşı monitorinqi gücləndirməlidir.
This vendor's CVEs17
- CVE-2026-73618EPSS 0.29%
- CVE-2026-73617EPSS 0.20%
- CVE-2026-73305EPSS 0.37%
- CVE-2026-73304EPSS 0.36%
- CVE-2026-73302EPSS 0.31%
- CVE-2026-73301EPSS 0.25%
- CVE-2026-72859EPSS 0.18%
- CVE-2026-72857EPSS 0.26%
- CVE-2026-72856EPSS 0.33%
- CVE-2026-72855EPSS 0.27%
- CVE-2026-72853EPSS 0.24%
- CVE-2026-72851EPSS 0.29%
- CVE-2026-72850EPSS 0.42%
- CVE-2026-72849EPSS 0.12%
- CVE-2026-67311EPSS 0.26%
- CVE-2026-54356EPSS 0.24%
- CVE-2026-35219EPSS 0.27%
This hub is built from skopnix's own reporting on Budibase: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.