Budibase 服务器在 3.45.0 版本之前,在向外部分享表格更新信息到 Builder 协作 WebSocket 房间之前,未能对明文的数据源凭据进行脱敏处理。拥有 Builder 访问权限的攻击者可以通过监控表格保存或删除操作,拦截到未脱敏的数据源对象,从而获取数据库密码和 API 密钥。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100682 | 8.8 HIGH | Budibase Server before 3.45.0 Arbitrary File Write via ZIP Symlink |
| CVE-2026-100686 | 8.1 HIGH | Budibase before 3.45.0 Cross-Workspace Privilege Escalation via POST /api/global/groups/:g |
| CVE-2026-100684 | 8.1 HIGH | Budibase Server 3.41.0 before 3.45.0 Authentication Bypass via OIDC |
| CVE-2026-100680 | 8.1 HIGH | Budibase before 3.45.0 Arbitrary Local File Read via OpenAPI Import |
| CVE-2026-100683 | 8.0 HIGH | Budibase before 3.45.0 SQL Injection via column-rename DDL |
| CVE-2026-100685 | 7.7 HIGH | Budibase before 3.45.0 Information Disclosure via Chat Links |
| CVE-2026-100688 | 6.5 MEDIUM | Budibase server before 3.45.0 Cross-Tenant Information Disclosure |
| CVE-2026-100681 | 5.4 MEDIUM | Budibase before 3.45.0 SSRF and OAuth Token Exfiltration via Teams Webhook |
No comments yet