Server-Side Request Forgery Vulnerability in Budibase Server
CVE-2026-82246
7.1HIGH
What is CVE-2026-82246?
Budibase Server prior to version 3.41.3 has a vulnerability that allows attackers to exploit the query import endpoint. This flaw occurs due to the server's inability to properly validate user-provided URLs before making requests to them. As a result, an attacker can send malicious URLs to access internal services, including sensitive cloud metadata endpoints and other protected network resources. Such exploitation can lead to unauthorized data exposure and potential further compromise of the affected environment.
Affected Version(s)
server 0 < 3.41.3
server 3.41.3
