PT-2026-83098 · Budibase · @Budibase/Server

·

CVE-2026-82246

·

Published

2026-08-28

·

Updated

2026-08-28

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Budibase Server versions prior to 3.41.3
Description An issue exists in the query import endpoint where the system fails to validate user-supplied URLs before fetching content. This allows attackers to perform a Server-Side Request Forgery (SSRF)—a technique where a server is tricked into making requests to an unintended location—to retrieve responses from internal services, including cloud metadata endpoints and other restricted network resources.
Recommendations Update Budibase Server to version 3.41.3 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82246
GHSA-48X3-9PH2-P9GJ

Affected Products

@Budibase/Server