Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Csidhant

#45878of 57,409
6.3Total CVSS
Vulnerabilities · 1
PT-2026-99352
6.3
2026-09-26
Budibase · Budibase · CVE-2026-100681
**Name of the Vulnerable Software and Affected Versions** Budibase versions prior to 3.45.0 **Description** An unauthenticated server-side request forgery (SSRF) and credential exfiltration issue exists in the Microsoft Teams webhook endpoint. The system accepts forged Bot Framework activities containing arbitrary `serviceUrl` values. An attacker can send a crafted POST request to inject a controlled `serviceUrl` that is persisted and used for all subsequent bot replies. This results in the server sending live Microsoft OAuth access tokens within Authorization headers to the attacker's host and allows for blind internal network access. **Recommendations** Update Budibase to version 3.45.0 or later.