CVE-2026-41428Disclosure(budibase / budibase)

LOWCVSS 9.1 · CRITICAL

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Patch budibase budibase systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Budibase is an open-source low-code platform. Prior to 3.35.4, the authenticated middleware uses unanchored regular expressions to match public (no-auth) endpoint patterns against ctx.request.url. Since ctx.request.url in Koa includes the query string, an attacker can access any protected endpoint by appending a public endpoint path as a query parameter. For example, POST /api/global/users/search?x=/api/system/status bypasses all authentication because the regex /api/system/status/ matches in the query string portion of the URL. This vulnerability is fixed in 3.35.4.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • budibase

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked at 5 mentions on most recent observed day (2026-05-21)
  • 6 total mentions across 2 days

Affected systems

Vendors
Products
budibase

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-04-24: 1Mentions · 2026-05-21: 5Patch / Workaround · 2026-04-24: 1Patch / Workaround · 2026-05-21: 2Technical Details · 2026-04-24: 1Technical Details · 2026-05-21: 304-2405-21
Signal classification3 categories
Disclosure
233.3%
General
233.3%
Patch
233.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-241
Disclosure1
2026-05-215
Disclosure1General2Patch2
Full discourse6 posts
  • Lyrie.ai@lyrie_ai
    Patch

    TL;DR Budibase versions prior to 3.35.4 contain a critical authentication bypass flaw (CVE-2026-41428, CVSS 9.1) that allows unauthenticated attackers to access protected API endpoints. The root cause: unanchored regular expressions in the auth middleware. Update…

    Post summary

    Budibase versions before 3.35.4 are vulnerable to CVE-2026-41428, a critical authentication bypass flaw; updating to the latest release resolves the issue.

    1000038
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    What Happened On April 24, 2026, security researchers disclosed CVE-2026-41428, a critical authentication bypass vulnerability in the open-source Budibase low-code platform. The flaw affects all versions prior to 3.35.4 and allows an attacker with network access to…

    Post summary

    The snippet announces CVE-2026-41428, an authentication bypass affecting Budibase versions before 3.35.4, without providing PoC, exploitation, or patch details.

    1000041
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    Sources TheHackerWire - Budibase Critical Auth Bypass via Unanchored Regex (CVE-2026-41428) NVD - CVE-2026-41428 Budibase GitHub - Release 3.35.4 CVSS 4.0 Scoring

    Post summary

    CVE-2026-41428 is a critical authentication bypass in Budibase caused by unanchored regex, but the vulnerability has been patched in release 3.35.4 with a CVSS 4.0 score provided.

    1000056
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/2026-04-26-budibase-auth-bypass-cve-2026-41428 #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    A research link about CVE‑2026‑41428 is shared, but the post contains no detailed technical info, exploit code, or mitigation guidance.

    0000030
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/2026-04-26-budibase-auth-bypass-cve-2026-41428 #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The post only includes a URL and generic tags, providing no concrete evidence or details about the CVE.

    0000028
    227 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41428 Budibase is an open-source low-code platform. Prior to 3.35.4, the authenticated middleware uses unanchored regular expressions to match public (no-auth) endpoint pat… https://www.cve.org/CVERecord?id=CVE-2026-41428

    Post summary

    CVE‑2026‑41428 affects Budibase's authenticated middleware by using unanchored regexes for public endpoints, allowing bypass; the issue is mitigated in version 3.35.4.

    0000078
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbudibasebudibase---

Explore more