PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-100680 budibase CVE debrief

Budibase server versions before 3.45.0 are vulnerable to arbitrary local file reads via OpenAPI import. Authenticated builders can exploit this by embedding file:// references in OpenAPI specifications to exfiltrate sensitive files, including environment variables with JWT secrets, API keys, and database credentials. This vulnerability has a high CVSS score of 8.6, indicating a high severity. The CVE record and source item provide details on the vulnerability, including affected versions and potential impacts.

Vendor
budibase
Product
server
CVSS
HIGH 8.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-26
Original CVE updated
2026-10-08
Advisory published
2026-09-26
Advisory updated
2026-10-08

Who should care

Budibase server administrators, developers, and security teams should assess exposure and prioritize upgrading to version 3.45.0 or later. Restricting OpenAPI import access and monitoring for suspicious activity are also recommended.

Why it matters

CVE-2026-100680 is a high-severity vulnerability in Budibase server versions before 3.45.0, allowing authenticated builders to read arbitrary local files via OpenAPI import. Defenders should prioritize upgrading to version 3.45.0 or later, restricting OpenAPI import access, and monitoring for suspicious activity. The vulnerability's impact is supported by the CVE record and source item, but actual exploitation and victim organizations are not reported.

  • Potential exfiltration of sensitive files, including environment variables with JWT secrets, API keys, and database credentials.
  • Possible disruption of service due to unauthorized access to sensitive files.
  • Need for verification of affected versions and exposure in specific deployment contexts.
  • Priority for upgrading to version 3.45.0 or later and restricting OpenAPI import access.

Technical summary

Budibase server versions before 3.45.0 fail to disable external JSON reference resolution in the OpenAPI/Swagger import validator. This allows authenticated builders to read arbitrary local files by embedding file:// references in OpenAPI specifications submitted to the import endpoint. The vulnerability is caused by the lack of proper validation and sanitization of user-input data, which enables attackers to access sensitive files and data. The CVE record and source item provide details on the vulnerability, including affected versions and potential impacts.

Defensive priority

High priority for Budibase server administrators to upgrade to version 3.45.0 or later and restrict OpenAPI import access.

Recommended defensive actions

  • Upgrade Budibase server to version 3.45.0 or later
  • Restrict access to OpenAPI import functionality
  • Monitor for suspicious activity related to OpenAPI imports
  • Review and update environment variables and sensitive files
  • Perform a thorough review of the system for any signs of exploitation
  • Implement additional monitoring and logging to detect potential attacks
  • Conduct a comprehensive risk assessment to identify potential vulnerabilities

Evidence notes

The CVE record and source item provide details on the vulnerability, including affected versions and potential impacts. However, limited information is available on actual exploitation or victim organizations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-100680 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-100680

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-100680 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100680

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Budibase before 3.45.0 Arbitrary Local File Read via OpenAPI Import

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/100xxx/CVE-2026-100680.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Budibase/budibase/security/advisories/GHSA-8xr5-pggf-26jq

    Supplemental source - vendor-advisory

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/budibase-before-3.45.0-arbitrary-local-file-read-via-openapi-import

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.