PT-2026-99358 · Budibase · @Budibase/Server

·

CVE-2026-100687

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v4.0

7.0

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Budibase Server versions prior to 3.45.0
Description The software fails to redact plaintext datasource credentials when broadcasting external table updates to the Builder collaboration websocket room. Users with Builder access can intercept unredacted datasource objects, which may contain sensitive information such as database passwords and API keys, by observing table save or delete operations.
Recommendations Update Budibase Server to version 3.45.0 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100687
GHSA-RMV5-3XPJ-W885

Affected Products

@Budibase/Server