This is a summary of the AI-generated 10-question deep analysis. The full version (longer answers, follow-up Q&A, related CVEs) requires login.
Read the full analysis โ
Q1What is this vulnerability? (Essence + Consequences)
๐จ **Essence**: Budibase has an **Authorization Bypass** flaw. ๐ **Consequences**: Attackers can skip authentication entirely. They access protected internal apps/workflows as if they were public.โฆ
๐ก๏ธ **Root Cause**: **CWE-287** (Improper Authentication). ๐ **Flaw**: Middleware uses a **non-anchored regex** to match public endpoints. It fails to anchor the start/end of the URL string.โฆ
๐ **Attacker Actions**: Bypass all login screens. ๐ **Data Access**: Read/Write internal apps, workflows, and admin panels. ๐ **Privileges**: Gain full control over internal business logic without valid credentials.โฆ
โก **Threshold**: **LOW**. ๐ **Auth**: Requires **NO** prior authentication (PR:N). ๐ฏ **Config**: Simple URL parameter injection. ๐ง **Skill**: Low complexity (AC:L). Any attacker can exploit this easily.
Q6Is there a public Exp? (PoC/Wild Exploitation)
๐ **Public Exploit**: **No** specific PoC code provided in data. ๐ **Status**: Advisory published (GHSA-8783-3wgf-jggf). โ ๏ธ **Risk**: Logic flaw is trivial to exploit manually via URL manipulation, even without a script.
Q7How to self-check? (Features/Scanning)
๐ **Self-Check**: Scan for Budibase instances. ๐งช **Test**: Try appending public endpoint paths as query parameters to protected URLs.โฆ
โ **Fix**: **Yes**, officially patched. ๐ **Patch Date**: 2026-04-24. ๐ **Action**: Upgrade to **Budibase 3.35.4** or later immediately. The regex anchoring issue is resolved in the new version.
Q9What if no patch? (Workaround)
๐ **No Patch Workaround**: Hard to mitigate technically. ๐งฑ **Defense**: Use a **WAF** (Web Application Firewall) to block suspicious URL patterns. ๐ **Network**: Restrict access to Budibase ports via firewall rules.โฆ
๐ฅ **Urgency**: **CRITICAL**. ๐จ **Priority**: Patch **IMMEDIATELY**. โ๏ธ **Reason**: CVSS is high, no auth required, and it exposes internal business data. Do not wait. Update to v3.35.4 now.