Data Exposure Vulnerability in Budibase Server by Budibase
CVE-2026-100687
7HIGH
What is CVE-2026-100687?
Budibase Server prior to version 3.45.0 has a significant vulnerability where plaintext datasource credentials are not redacted. This lack of redaction allows attackers with Builder access to intercept sensitive information like database passwords and API keys during table save or delete actions through the Builder collaboration websocket room. Such exposure poses a severe risk to the integrity and security of database interactions, as these credentials can be exploited for unauthorized access.
Affected Version(s)
server 0 < 3.45.0
server 3.45.0
