PT-2026-83095 · Budibase · @Budibase/Server

·

CVE-2026-82243

·

Published

2026-08-28

·

Updated

2026-08-28

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Budibase Server versions prior to 3.41.3
Description A server-side request forgery (SSRF) issue exists in the datasource verify endpoint. This allows users with builder-level permissions to provide arbitrary URLs that are not properly validated. An attacker can use this to leak internal CouchDB credentials by directing requests to a server under their control, potentially leading to full database access in cloud deployments.
Recommendations Update Budibase Server to version 3.41.3 or later. Restrict access to the datasource verify endpoint to minimize the risk of exploitation.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82243
GHSA-83M5-FVMG-R7XV

Affected Products

@Budibase/Server