Goal Reached Thanks to every supporter โ€” we hit 100%!

Goal: 1000 CNY ยท Raised: 1359 CNY

100%

CVE-2026-41428 โ€” AI Deep Analysis Summary

CVSS 9.1 ยท Critical

Q1What is this vulnerability? (Essence + Consequences)

๐Ÿšจ **Essence**: Budibase has an **Authorization Bypass** flaw. ๐Ÿ“‰ **Consequences**: Attackers can skip authentication entirely. They access protected internal apps/workflows as if they were public.โ€ฆ

Q2Root Cause? (CWE/Flaw)

๐Ÿ›ก๏ธ **Root Cause**: **CWE-287** (Improper Authentication). ๐Ÿ› **Flaw**: Middleware uses a **non-anchored regex** to match public endpoints. It fails to anchor the start/end of the URL string.โ€ฆ

Q3Who is affected? (Versions/Components)

๐Ÿข **Vendor**: Budibase (UK-based low-code platform). ๐Ÿ“ฆ **Affected**: Versions **before 3.35.4**. ๐Ÿ–ฅ๏ธ **Component**: The authentication middleware handling `ctx.request.url`.

Q4What can hackers do? (Privileges/Data)

๐Ÿ’€ **Attacker Actions**: Bypass all login screens. ๐Ÿ“‚ **Data Access**: Read/Write internal apps, workflows, and admin panels. ๐Ÿš€ **Privileges**: Gain full control over internal business logic without valid credentials.โ€ฆ

Q5Is exploitation threshold high? (Auth/Config)

โšก **Threshold**: **LOW**. ๐Ÿ“ **Auth**: Requires **NO** prior authentication (PR:N). ๐ŸŽฏ **Config**: Simple URL parameter injection. ๐Ÿง  **Skill**: Low complexity (AC:L). Any attacker can exploit this easily.

Q6Is there a public Exp? (PoC/Wild Exploitation)

๐Ÿ” **Public Exploit**: **No** specific PoC code provided in data. ๐ŸŒ **Status**: Advisory published (GHSA-8783-3wgf-jggf). โš ๏ธ **Risk**: Logic flaw is trivial to exploit manually via URL manipulation, even without a script.

Q7How to self-check? (Features/Scanning)

๐Ÿ”Ž **Self-Check**: Scan for Budibase instances. ๐Ÿงช **Test**: Try appending public endpoint paths as query parameters to protected URLs.โ€ฆ

Q8Is it fixed officially? (Patch/Mitigation)

โœ… **Fix**: **Yes**, officially patched. ๐Ÿ“… **Patch Date**: 2026-04-24. ๐Ÿ”„ **Action**: Upgrade to **Budibase 3.35.4** or later immediately. The regex anchoring issue is resolved in the new version.

Q9What if no patch? (Workaround)

๐Ÿ›‘ **No Patch Workaround**: Hard to mitigate technically. ๐Ÿงฑ **Defense**: Use a **WAF** (Web Application Firewall) to block suspicious URL patterns. ๐Ÿ”’ **Network**: Restrict access to Budibase ports via firewall rules.โ€ฆ

Q10Is it urgent? (Priority Suggestion)

๐Ÿ”ฅ **Urgency**: **CRITICAL**. ๐Ÿšจ **Priority**: Patch **IMMEDIATELY**. โš–๏ธ **Reason**: CVSS is high, no auth required, and it exposes internal business data. Do not wait. Update to v3.35.4 now.