CVE-2026-100687 PUBLISHED

Budibase Server before 3.45.0 Credential Exposure via External Table Broadcast

Assigner: VulnCheck
Reserved: 26.09.2026 Published: 26.09.2026 Updated: 26.09.2026

Budibase Server before 3.45.0 fails to redact plaintext datasource credentials before broadcasting external table updates to the Builder collaboration websocket room. Attackers with Builder access can intercept unredacted datasource objects containing database passwords and API keys by observing table save or delete operations.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 7

Product Status

Vendor budibase
Product server
Versions Default: unaffected
  • affected from 0 to 3.45.0 (excl.)
  • Version 3.45.0 is unaffected

Credits

  • iaohkut-from-NightWolf-Team reporter

References

Problem Types

  • Exposure of Sensitive Information to an Unauthorized Actor CWE