CVE-2026-73410

8.5

Budibase · budibase

Budibase is affected by a combination of Time-of-check Time-of-use (TOCTOU) race conditions and Server-Side Request Forgery (SSRF) vulnerabilities.

Executive summary

Budibase versions prior to 3.40.0 are vulnerable to race conditions and SSRF, which could allow an authenticated attacker to bypass security controls or perform unauthorized requests.

Vulnerability

This vulnerability involves a TOCTOU race condition and SSRF flaws that allow an authenticated user to perform unauthorized actions or interact with internal systems. The attack requires low privileges and can lead to significant security bypasses.

Business impact

The identified vulnerabilities pose a high risk to organizational data and infrastructure. An attacker could potentially leverage SSRF to scan or interact with internal network resources that are otherwise inaccessible from the public internet. Given the CVSS score of 8.5, this issue is critical, as it allows for total technical impact, including data exfiltration or internal service disruption.

Remediation

Immediate Action: Upgrade to Budibase version 3.40.0 or later to apply the necessary security patches.

Proactive Monitoring: Inspect server logs for unusual outbound connection patterns or unexpected internal API access logs that deviate from established baselines.

Compensating Controls: Ensure that the Budibase instance is deployed within a segmented network environment with strict egress filtering to limit the reach of potential SSRF attempts.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this issue necessitates an immediate update to the latest patched version. Administrators should prioritize this deployment to prevent potential exploitation of the platform's internal network access capabilities.

More Budibase CVEs