CVE-2026-82246
Last modified
CVE-2026-82246 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the query import endpoint that fails to validate user-supplied URLs before fetching content. Attackers can submit arbitrary URLs to retrieve responses from internal services including cloud metadata endpoints and other restricted network resources..
Description
Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the query import endpoint that fails to validate user-supplied URLs before fetching content. Attackers can submit arbitrary URLs to retrieve responses from internal services including cloud metadata endpoints and other restricted network resources.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| budibase | server | < 3.41.3 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-82246?
How severe is CVE-2026-82246?
How do I fix CVE-2026-82246?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-82240Budibase before 3.41.3 fails to validate app-scoped builder …8.1
- CVE-2026-82241Budibase backend-core (@budibase/backend-core, as used by @b…7.1
- CVE-2026-82242Budibase versions before 3.41.3 contain a missing authorizat…7.7
- CVE-2026-82243Budibase Server before 3.41.3 contains a server-side request…7.6
- CVE-2026-82244Budibase versions before 3.41.3 contain a remote code execut…9.1
- CVE-2026-82245Budibase before 3.41.3 fails to enforce role-based authoriza…8.1
- CVE-2026-82247gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a…7.5
- CVE-2026-82248gix-worktree-state before 0.33.0 (part of gitoxide) allows w…5.3
- CVE-2026-82249gitoxide before 0.38.2 fails to validate carriage return cha…3.1
- CVE-2026-8225A vulnerability was identified in Open5GS up to 2.7.7. This …7.5
- CVE-2026-82250gitoxide gix-packetline versions before 0.21.5 contain a pan…6.5
- CVE-2026-82251gitoxide before 0.52.1 fails to validate submodule names fro…7.5
Are you affected by CVE-2026-82246?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
