Server-Side Request Forgery in Budibase Low-Code Platform
CVE-2026-33226

8.7HIGH

Key Information:

Vendor

Budibase

Status
Vendor
CVE Published:
20 March 2026

What is CVE-2026-33226?

The Budibase low-code platform, up to version 3.30.6, suffers from a server-side request forgery vulnerability due to the REST datasource query preview endpoint allowing unauthenticated server-side HTTP requests. This flaw enables authenticated administrators to access internal services that should not be publicly exposed, putting sensitive systems and data at significant risk. Particularly on Google Cloud Platform, this vulnerability can lead to the theft of OAuth2 tokens, potentially granting full access to GCP resources. Furthermore, it allows comprehensive internal network enumeration without validation on user-provided URLs, exacerbating security concerns for deployments. As of publication, no patches are available.

Affected Version(s)

budibase <= 3.30.6

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.