Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.4 and earlier, the Budibase server's authorized() middleware that protects every server-side API endpoint can be completely bypassed by appending a webhook path pattern to the query string of any request. The isWebhookEndpoint() function uses an unanchored regex that tests against ctx.request.url
VulnCheck: Budibase is
Exploit
CVE-2026-31816
VulnCheck
Refer to CVE-2026-31816 NVD advisory