CVE-2026-100680: Exposure of Sensitive Information to an Unauthorized Actor in budibase server
Budibase versions before 3.45.0 fail to disable external JSON reference resolution in the OpenAPI/Swagger import validator, allowing authenticated builders to read arbitrary local files. Attackers with builder access can embed file:// references in OpenAPI specifications submitted to the import endpoint to exfiltrate sensitive files including environment variables containing JWT secrets, API keys, and database credentials.
AI Analysis
Technical Summary
CVE-2026-100680 affects Budibase server versions prior to 3.45.0. The vulnerability arises from the failure to disable external JSON reference resolution in the OpenAPI/Swagger import validator. Authenticated users with builder access can exploit this by submitting OpenAPI specifications containing file:// references to the import endpoint, which results in arbitrary local file disclosure. This can lead to exposure of sensitive data including environment variables that hold JWT secrets, API keys, and database credentials.
Potential Impact
An attacker with authenticated builder privileges can read arbitrary local files on the Budibase server, potentially exposing highly sensitive information such as JWT secrets, API keys, and database credentials. This can compromise the confidentiality of the system and lead to further unauthorized access or data breaches.
Mitigation Recommendations
Upgrade Budibase server to version 3.45.0 or later where this vulnerability is fixed. Versions prior to 3.45.0 are affected. No other mitigation or temporary fix is indicated. Patch status is confirmed by the versioning information provided.
CVE-2026-100680: Exposure of Sensitive Information to an Unauthorized Actor in budibase server
Description
Budibase versions before 3.45.0 fail to disable external JSON reference resolution in the OpenAPI/Swagger import validator, allowing authenticated builders to read arbitrary local files. Attackers with builder access can embed file:// references in OpenAPI specifications submitted to the import endpoint to exfiltrate sensitive files including environment variables containing JWT secrets, API keys, and database credentials.
CVSS v4.0
Score 8.6high
Affected software
budibase
server
pkg:github/budibase/budibaseRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-100680 affects Budibase server versions prior to 3.45.0. The vulnerability arises from the failure to disable external JSON reference resolution in the OpenAPI/Swagger import validator. Authenticated users with builder access can exploit this by submitting OpenAPI specifications containing file:// references to the import endpoint, which results in arbitrary local file disclosure. This can lead to exposure of sensitive data including environment variables that hold JWT secrets, API keys, and database credentials.
Potential Impact
An attacker with authenticated builder privileges can read arbitrary local files on the Budibase server, potentially exposing highly sensitive information such as JWT secrets, API keys, and database credentials. This can compromise the confidentiality of the system and lead to further unauthorized access or data breaches.
Mitigation Recommendations
Upgrade Budibase server to version 3.45.0 or later where this vulnerability is fixed. Versions prior to 3.45.0 are affected. No other mitigation or temporary fix is indicated. Patch status is confirmed by the versioning information provided.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-26T02:36:51.809Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab7c9abf7a7c5410652fd4b
Added to database: 09/26/2026, 13:33:31 UTC
Last enriched: 09/26/2026, 13:48:45 UTC
Last updated: 09/27/2026, 04:31:26 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.