top of page
perceptive_background_267k.jpg

Budibase is an open-source low-code platform. Prior to 3.39.0, the single-datasource GET and PUT routes are guarded by generic TABLE READ, not by Builder/Admin …

Published:

26 May 2026 at 22:00:00

Alert date:

27 May 2026 at 19:08:13

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

Budibase, an open-source low-code platform, has a vulnerability prior to version 3.39.0 where single-datasource GET and PUT routes are inadequately protected. The vulnerability allows Basic users to exploit inadequate permission checks on datasource routes. Attackers can manipulate REST datasource configurations by changing the config.url while keeping redacted placeholders. During query execution, the platform discloses builder-configured REST Authorization secrets to attacker-controlled listeners. The issue stems from generic TABLE READ permissions instead of proper Builder/Admin or datasource-specific checks. This results in server-side disclosure of sensitive authorization credentials to unauthorized parties.

Technical details

Mitigation steps:

Affected products:

Budibase

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page