top of page
perceptive_background_267k.jpg

Budibase is an open-source low-code platform. Prior to 3.38.1, Budibase exposes a REST API for datasource management. The route PUT /api/datasources/:datasource…

Published:

26 mei 2026 om 22:00:00

Alert date:

27 mei 2026 om 19:08:13

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Database & Storage, Enterprise Applications

Budibase open-source low-code platform prior to version 3.38.1 contains an authorization bypass vulnerability in its REST API for datasource management. The PUT /api/datasources/:datasourceId endpoint uses incorrect TABLE/READ permissions instead of proper write permissions, allowing any authenticated user with BASIC role to modify datasource configurations. Attackers can rewrite database connection details including host, port, and credentials. The vulnerability enables Server-Side Request Forgery (SSRF) attacks against internal services through PostgreSQL/MySQL/MongoDB connections due to lack of network-level protection. This allows probing and interaction with internal services on arbitrary ports.

Technical details

Mitigation steps:

Affected products:

Budibase

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page