


Perceptive Security
SOC/SIEM Consultancy

Budibase is an open-source low-code platform. Prior to 3.39.0, the single-datasource GET and PUT routes are guarded by generic TABLE READ, not by Builder/Admin …
Published:
26 May 2026 at 22:00:00
Alert date:
27 May 2026 at 19:08:13
Source:
nvd.nist.gov
Web Technologies, Identity & Access
Budibase, an open-source low-code platform, has a vulnerability prior to version 3.39.0 where single-datasource GET and PUT routes are inadequately protected. The vulnerability allows Basic users to exploit inadequate permission checks on datasource routes. Attackers can manipulate REST datasource configurations by changing the config.url while keeping redacted placeholders. During query execution, the platform discloses builder-configured REST Authorization secrets to attacker-controlled listeners. The issue stems from generic TABLE READ permissions instead of proper Builder/Admin or datasource-specific checks. This results in server-side disclosure of sensitive authorization credentials to unauthorized parties.
Technical details
Mitigation steps:
Affected products:
Budibase
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-48152
https://github.com/Budibase/budibase/security/advisories/GHSA-3gp5-q4jw-3v94
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
