CVE-2026-73410
8.5Budibase · budibase
Budibase is affected by a combination of Time-of-check Time-of-use (TOCTOU) race conditions and Server-Side Request Forgery (SSRF) vulnerabilities.
Executive summary
Budibase versions prior to 3.40.0 are vulnerable to race conditions and SSRF, which could allow an authenticated attacker to bypass security controls or perform unauthorized requests.
Vulnerability
This vulnerability involves a TOCTOU race condition and SSRF flaws that allow an authenticated user to perform unauthorized actions or interact with internal systems. The attack requires low privileges and can lead to significant security bypasses.
Business impact
The identified vulnerabilities pose a high risk to organizational data and infrastructure. An attacker could potentially leverage SSRF to scan or interact with internal network resources that are otherwise inaccessible from the public internet. Given the CVSS score of 8.5, this issue is critical, as it allows for total technical impact, including data exfiltration or internal service disruption.
Remediation
Immediate Action: Upgrade to Budibase version 3.40.0 or later to apply the necessary security patches.
Proactive Monitoring: Inspect server logs for unusual outbound connection patterns or unexpected internal API access logs that deviate from established baselines.
Compensating Controls: Ensure that the Budibase instance is deployed within a segmented network environment with strict egress filtering to limit the reach of potential SSRF attempts.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this issue necessitates an immediate update to the latest patched version. Administrators should prioritize this deployment to prevent potential exploitation of the platform's internal network access capabilities.