← العودة للجدول
CVE-2026-31816
CVE-2026-31816 — VulnCheck: Budibase is a low code platform for creating internal tools, workflows
📅 2026-03-09
🔴 Critical 🔥 No VulnCheck Exploit Web CVSS 9.1

📋 الوصف الكامل

Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.4 and earlier, the Budibase server's authorized() middleware that protects every server-side API endpoint can be completely bypassed by appending a webhook path pattern to the query string of any request. The isWebhookEndpoint() function uses an unanchored regex that tests against ctx.request.url

💻 الأنظمة المتأثرة

VulnCheck: Budibase is

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-31816

📡 المصدر

VulnCheck

✅ الحلول والتخفيف

Refer to CVE-2026-31816 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←