Information Disclosure in Budibase Low-Code Platform
CVE-2026-46427

7.7HIGH

Key Information:

Vendor

Budibase

Status
Vendor
CVE Published:
27 May 2026

What is CVE-2026-46427?

Budibase, an open-source low-code platform, has a vulnerability that allows unauthorized access to sensitive data. The issue arises from how the platform handles the removal of secrets in its datasource configurations. Specifically, prior to version 3.38.3, the system fails to mask the privateKey field associated with Snowflake integrations due to a misconfiguration. This oversight permits an authenticated user to access the private key in plaintext by calling an API endpoint designed for authorized users. The vulnerability has been addressed in version 3.38.3, reinforcing the importance of keeping software updated to protect sensitive information.

Affected Version(s)

budibase < 3.38.3

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.