


Perceptive Security
SOC/SIEM Consultancy

Budibase is an open-source low-code platform. Prior to 3.38.3, removeSecrets at packages/server/src/sdk/workspace/datasources/datasources.ts masks only datasour…
Published:
26 mei 2026 om 22:00:00
Alert date:
27 mei 2026 om 20:13:41
Source:
nvd.nist.gov
Web Technologies, Database & Storage
Budibase open-source low-code platform vulnerability allows authenticated BASIC users to retrieve Snowflake private keys in plaintext. The issue occurs because the removeSecrets function only masks PASSWORD type fields but skips SENSITIVE_LONGFORM fields like Snowflake's privateKey. Authenticated users with basic permissions can exploit the GET /api/datasources/:datasourceId endpoint to access full PEM keys. The vulnerability affects versions prior to 3.38.3 and has been patched in version 3.38.3.
Technical details
Mitigation steps:
Affected products:
Budibase
Snowflake
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-46427
https://github.com/Budibase/budibase/security/advisories/GHSA-qv26-4hvj-m7fv
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
