Security Flaw in Budibase Low-Code Platform Exposing Credentials
CVE-2026-73407

9CRITICAL

Key Information:

Vendor

Budibase

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-73407?

Budibase, an open-source low-code platform, is affected by a vulnerability in its RestIntegration component. Before version 3.40.1, this issue allowed unauthenticated users to exploit a public API endpoint. An attacker could craft a query that interacts with a malicious host, potentially exposing sensitive authentication credentials such as bearer keys and static headers. This serious oversight highlights the importance of stringent validation for request origins against data source configurations. The vulnerability has been addressed in version 3.40.1, emphasizing the need for users to update their installations to maintain security.

Affected Version(s)

budibase < 3.40.1

References

CVSS V4

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.