Description
Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the datasource verify endpoint that allows builder-level users to supply arbitrary URLs without SSRF validation. Attackers can exploit this to leak internal CouchDB credentials by making requests to attacker-controlled servers, gaining full database access in cloud deployments.
Published: 2026-08-28
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Credential Leakage via SSRF
Action: Patch
AI Analysis

Impact

The vulnerability is a server‑side request forgery in the datasource verify endpoint of Budibase Server. Builder‑level users can supply any URL without SSRF validation, causing the server to fetch resources from internal or external targets. By directing requests to attacker‑controlled servers, an adversary can capture CouchDB credentials that the Server uses, granting full access to the internal database. This weakness is classified as CWE‑918, which is a credential leakage via SSRF.

Affected Systems

Budibase Server versions older than 3.41.3 are affected. The flaw is present in the Budibase Server product, which allows builder‑level users to provide arbitrary URLs to the datasources verify endpoint without proper validation.

Risk and Exploitability

The CVSS score is 8.3, indicating high severity. The EPSS score is not available and the issue is not listed in the CISA KEV catalog. Exploitation requires authenticated builder‑level access to the web interface, but once executed, the attacker obtains internal CouchDB credentials and can read or modify all data in the database in cloud deployments.

Generated by OpenCVE AI on August 28, 2026 at 14:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Budibase Server to version 3.41.3 or newer
  • If an upgrade is not immediately possible, restrict builder‑level users from accessing the datasource verify endpoint or block outbound connections from that endpoint using network controls
  • Monitor outbound requests originating from the datasource verify endpoint, and alert on traffic to uncommon external domains

Generated by OpenCVE AI on August 28, 2026 at 14:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Budibase server
Vendors & Products Budibase server

Fri, 28 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Description Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the datasource verify endpoint that allows builder-level users to supply arbitrary URLs without SSRF validation. Attackers can exploit this to leak internal CouchDB credentials by making requests to attacker-controlled servers, gaining full database access in cloud deployments.
Title Budibase Server before 3.41.3 SSRF with Credential Leakage
First Time appeared Budibase
Budibase budibase
Weaknesses CWE-918
CPEs cpe:2.3:a:budibase:budibase:*:*:*:*:*:*:*:*
Vendors & Products Budibase
Budibase budibase
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N'}


Subscriptions

Budibase Budibase Server
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-31T18:31:42.022Z

Reserved: 2026-08-28T10:37:51.948Z

Link: CVE-2026-82243

cve-icon Vulnrichment

Updated: 2026-08-31T18:31:30.364Z

cve-icon NVD

Status : Deferred

Published: 2026-08-28T12:16:34.477

Modified: 2026-08-31T19:17:16.160

Link: CVE-2026-82243

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T15:45:02Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)