PT-2026-99352 · Budibase · Budibase

·

CVE-2026-100681

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v4.0

6.3

Medium

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Budibase versions prior to 3.45.0
Description An unauthenticated server-side request forgery (SSRF) and credential exfiltration issue exists in the Microsoft Teams webhook endpoint. The system accepts forged Bot Framework activities containing arbitrary serviceUrl values. An attacker can send a crafted POST request to inject a controlled serviceUrl that is persisted and used for all subsequent bot replies. This results in the server sending live Microsoft OAuth access tokens within Authorization headers to the attacker's host and allows for blind internal network access.
Recommendations Update Budibase to version 3.45.0 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100681
GHSA-942W-FCCR-8R3C

Affected Products

Budibase