在 Budibase 3.41.3 版本之前,软件未能对许可证管理端点实施基于角色的访问控制,这使得任何已认证的用户都可以删除许可证密钥或操作离线令牌。仅具备基本用户权限的攻击者可以访问 端点,从而禁用高级功能,并降级所有用户的部署环境。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82244 | 9.1 CRITICAL | Budibase before 3.41.3 Remote Code Execution via Plugin eval() |
| CVE-2026-82240 | 8.1 HIGH | Budibase before 3.41.3 Privilege Escalation via User Update API |
| CVE-2026-82239 | 8.1 HIGH | Budibase before 3.41.3 Authorization Bypass via datasources/query |
| CVE-2026-82242 | 7.7 HIGH | Budibase before 3.41.3 Cross-Application Resource Injection via Missing Authorization |
| CVE-2026-82243 | 7.6 HIGH | Budibase Server before 3.41.3 SSRF with Credential Leakage |
| CVE-2026-82246 | 7.1 HIGH | Budibase Server before 3.41.3 SSRF via Query Import |
| CVE-2026-82241 | 7.1 HIGH | Budibase backend-core SSRF via incomplete default blacklist |
No comments yet