CVE-2026-31816Disclosure(budibase / budibase)

MEDIUMCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch budibase budibase systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.4 and earlier, the Budibase server's authorized() middleware that protects every server-side API endpoint can be completely bypassed by appending a webhook path pattern to the query string of any request. The isWebhookEndpoint() function uses an unanchored regex that tests against ctx.request.url, which in Koa includes the full URL with query parameters. When the regex matches, the authorized() middleware immediately calls return next(), skipping all authentication, authorization, role checks, and CSRF protection. This means a completely unauthenticated, remote attacker can access any server-side API endpoint by simply appending ?/webhooks/trigger (or any webhook pattern variant) to the URL.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • budibase

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 3 mentions (2026-03-09); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
budibase

Deep dive

Activity timeline7 mentions / 5d
01223Mentions · 2026-03-09: 3Mentions · 2026-03-10: 1Mentions · 2026-03-12: 1Mentions · 2026-03-16: 1Mentions · 2026-03-25: 1PoC Mentioned / Linked · 2026-03-12: 1Exploit Tool / Code · 2026-03-12: 1Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-03-12: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-25: 103-0903-1003-1203-1603-25
Signal classification4 categories
Disclosure
457.1%
General
114.3%
Patch
114.3%
Exploit
114.3%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-093
Disclosure2General1
2026-03-101
Patch1
2026-03-121
Exploit1
2026-03-161
Disclosure1
2026-03-251
Disclosure1
Full discourse7 posts
  • Gray Hats@the_yellow_fall
    Patch

    Two critical flaws in Budibase (CVE-2026-31816, CVE-2026-30240) allow unauthenticated API access and secret exfiltration via path traversal. Patch immediately. https://securityonline.info/total-platform-compromise-critical-9-6-cvss-flaws-in-budibase-expose-production-secrets/ https://t.co/wQZGgJOhdC

    Post summary

    The tweet alerts that two critical Budibase CVEs enable unauthenticated API access and path traversal for secret exfiltration, urging immediate patching.

    02040357
    10.6K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-31816 - critical 🚨 Budibase - Authentication Bypass > Budibase <= 3.31.4 contains an authentication bypass caused by unanchored regex in au... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-31816 @pdnuclei #NucleiTemplates #cve

    Post summary

    Budibase versions up to 3.31.4 suffer a critical authentication bypass via an unanchored regex; the vulnerability is disclosed with technical details and a reference link, but no exploitable code, active exploitation, or patch is announced.

    00031163
    904 followersView on X
  • Morty@MortyJin
    Exploit

    I wrote a technical analysis of CVE-2026-31816 in Budibase. The vulnerability originates from an unanchored webhook regex in the authorized() middleware. Because the check uses ctx.request.url, attackers can inject /webhooks/ in the query string to bypass authentication. In certain scenarios, this can be chained to achieve RCE. Write-up: https://rustlang.rs/posts/CVE-2026-31816-EN/ https://github.com/imjdl/CVE-2026-31816-rshell https://github.com/Budibase/budibase/security/advisories/GHSA-gw94-hprh-4wj8 #infosec #security #cve

    Post summary

    The post offers a technical analysis of CVE‑2026‑31816, revealing a regex flaw that can bypass authentication and lead to RCE, includes a PoC repository, and cites a security advisory with patch details.

    01010141
    123 followersView on X
  • Chris@theshodandork
    Disclosure

    The auth bypass (CVE-2026-31816) works by appending "?/webhooks/trigger" to a Budibase API endpoint, an un-anchored regex in the server middleware matches this in the query string and skips all auth checks. The path traversal payloads (CVE-2026-30240) are crafted ZIP files containing icons.json with paths like "../../../../proc/1/environ", targeting the PWA upload endpoint to read server environment variables, which in Budibase deployments will possibly include database credentials, JWT secrets, and API keys.

    Post summary

    The text discloses technical details of two CVEs in Budibase: CVE-2026-31816 enables auth bypass by appending a specific query string, while CVE-2026-30240 uses path traversal in crafted ZIP files to read sensitive environment data. No proof of concept, exploit code, patch, or active exploitation is reported.

    1000093
    9 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-31816: CRITICAL] Budibase low-code platform's security vulnerability (3.31.4 and earlier) allows unauthenticated remote attackers to bypass server API endpoint protection via appending a webhook pa...#cve,CVE-2026-31816,#cybersecurity https://cvefind.com/CVE-2026-31816

    Post summary

    Budibase low‑code platform (v3.31.4 and earlier) has a critical vulnerability that allows unauthenticated remote attackers to bypass API endpoint protection via a webhook payload. No PoC, exploit code, patch, or active exploitation details are provided.

    0000045
    600 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-31816 Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.4 and earlier, the Budibase server's authorized() middleware that pr… https://www.cve.org/CVERecord?id=CVE-2026-31816

    Post summary

    The text references CVE-2026-31816 and notes affected Budibase versions, but provides no detailed technical, exploit, or mitigation information.

    0000080
    56.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-31816 - Critical Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.4 and earlier, the Budibase server's authorized() middleware that protects every server-s... https://www.thehackerwire.com/vulnerability/CVE-2026-31816/ https://t.co/VCrAH7r3Vg

    Post summary

    A critical CVE-2026-31816 affecting Budibase versions 3.31.4 and earlier is announced, highlighting a flaw in the authorized() middleware, but no details on PoC, exploits, patches, or active attacks are provided.

    0000041
    129 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbudibasebudibase---

Explore more