CVE-2026-100687
Last modified
CVE-2026-100687 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. Budibase Server before 3.45.0 fails to redact plaintext datasource credentials before broadcasting external table updates to the Builder collaboration websocket room. Attackers with Builder access can intercept unredacted datasource objects containing database passwords and API keys by observing table save or delete operations..
Description
Budibase Server before 3.45.0 fails to redact plaintext datasource credentials before broadcasting external table updates to the Builder collaboration websocket room. Attackers with Builder access can intercept unredacted datasource objects containing database passwords and API keys by observing table save or delete operations.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| budibase | server | < 3.45.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-100687?
How severe is CVE-2026-100687?
How do I fix CVE-2026-100687?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-100681Budibase before 3.45.0 contains an unauthenticated server-si…5.4
- CVE-2026-100682Budibase Server before 3.45.0 contains an arbitrary file wri…8.8
- CVE-2026-100683Budibase (@budibase/server) before 3.45.0 builds MySQL and M…8
- CVE-2026-100684Budibase versions 3.41.0 before 3.45.0 contain an authentica…8.1
- CVE-2026-100685Budibase before 3.45.0 fails to properly scope the GET /api/…7.7
- CVE-2026-100686Budibase versions before 3.45.0 fail to validate per-app aut…8.1
- CVE-2026-100688Budibase server before 3.45.0 contains a cross-tenant inform…6.5
- CVE-2026-100689GitPython before 3.1.62 does not validate the `path` field r…5.9
- CVE-2026-10069A vulnerability has been found in Shibby Tomato 1.28. The im…8.7
- CVE-2026-100690Hugo versions from v0.161.0 through v0.165.0 run Node.js too…7.5
- CVE-2026-100691Hugo versions 0.75.0 through 0.165.x contain a stored cross-…5.4
- CVE-2026-100692Hugo is a static site generator. In versions after v0.123.0 …7.5
Are you affected by CVE-2026-100687?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
