


Perceptive Security
SOC/SIEM Consultancy

Budibase is an open-source low-code platform. Prior to 3.38.3, removeSecrets at packages/server/src/sdk/workspace/datasources/datasources.ts masks only datasour…
Published:
26 mei 2026 om 22:00:00
Alert date:
27 mei 2026 om 19:08:13
Source:
nvd.nist.gov
Web Technologies, Database & Storage
CVE-2026-46427 affects Budibase, an open-source low-code platform, prior to version 3.38.3. The vulnerability exists in the removeSecrets function which only masks PASSWORD type fields but skips SENSITIVE_LONGFORM fields. This allows authenticated BASIC users to retrieve Snowflake private keys in plaintext through the GET /api/datasources/:datasourceId endpoint. The issue specifically affects Snowflake integration where private keys are typed as SENSITIVE_LONGFORM instead of PASSWORD, bypassing the security filter. The vulnerability has been fixed in Budibase version 3.38.3.
Technical details
Mitigation steps:
Affected products:
Budibase
Snowflake
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-46427
https://github.com/Budibase/budibase/security/advisories/GHSA-qv26-4hvj-m7fv
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
