Server-Side Request Forgery in Budibase Low-Code Platform
CVE-2026-33226
8.7HIGH
What is CVE-2026-33226?
The Budibase low-code platform, up to version 3.30.6, suffers from a server-side request forgery vulnerability due to the REST datasource query preview endpoint allowing unauthenticated server-side HTTP requests. This flaw enables authenticated administrators to access internal services that should not be publicly exposed, putting sensitive systems and data at significant risk. Particularly on Google Cloud Platform, this vulnerability can lead to the theft of OAuth2 tokens, potentially granting full access to GCP resources. Furthermore, it allows comprehensive internal network enumeration without validation on user-provided URLs, exacerbating security concerns for deployments. As of publication, no patches are available.
Affected Version(s)
budibase <= 3.30.6
