top of page
perceptive_background_267k.jpg

Budibase is an open-source low-code platform. Prior to 3.35.4, the authenticated middleware uses unanchored regular expressions to match public (no-auth) endpoi…

Published:

23 april 2026 om 22:00:00

Alert date:

24 april 2026 om 21:02:15

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

Budibase, an open-source low-code platform, contains an authentication bypass vulnerability in versions prior to 3.35.4. The vulnerability exists in the authenticated middleware which uses unanchored regular expressions to match public endpoint patterns against ctx.request.url. Since the URL includes query strings in Koa framework, attackers can bypass authentication by appending public endpoint paths as query parameters. For example, POST /api/global/users/search?x=/api/system/status bypasses authentication because the regex matches the query string portion. This allows unauthorized access to protected endpoints and has been fixed in version 3.35.4.

Technical details

Mitigation steps:

Affected products:

Budibase

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page