在 Budibase 3.41.3 之前的版本中,POST /api/datasources/query 接口未能正确执行基于表的角色限制,导致拥有较低权限的 BASIC 角色用户可以无视已配置的数据权限,读取、创建、更新或删除任意表中的数据。拥有 BASIC 角色的攻击者可以通过提交包含目标表标识符的构造查询请求,绕过表级访问控制,从而操作受限数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82244 | 9.1 CRITICAL | Budibase before 3.41.3 Remote Code Execution via Plugin eval() |
| CVE-2026-82240 | 8.1 HIGH | Budibase before 3.41.3 Privilege Escalation via User Update API |
| CVE-2026-82245 | 8.1 HIGH | Budibase before 3.41.3 Missing Authorization License Management |
| CVE-2026-82242 | 7.7 HIGH | Budibase before 3.41.3 Cross-Application Resource Injection via Missing Authorization |
| CVE-2026-82243 | 7.6 HIGH | Budibase Server before 3.41.3 SSRF with Credential Leakage |
| CVE-2026-82246 | 7.1 HIGH | Budibase Server before 3.41.3 SSRF via Query Import |
| CVE-2026-82241 | 7.1 HIGH | Budibase backend-core SSRF via incomplete default blacklist |
No comments yet