PatchSiren cyber security CVE debrief
CVE-2026-100680 budibase CVE debrief
Budibase server versions before 3.45.0 are vulnerable to arbitrary local file reads via OpenAPI import. Authenticated builders can exploit this by embedding file:// references in OpenAPI specifications to exfiltrate sensitive files, including environment variables with JWT secrets, API keys, and database credentials. This vulnerability has a high CVSS score of 8.6, indicating a high severity. The CVE record and source item provide details on the vulnerability, including affected versions and potential impacts.
- Vendor
- budibase
- Product
- server
- CVSS
- HIGH 8.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-26
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-09-26
- Advisory updated
- 2026-10-08
Who should care
Budibase server administrators, developers, and security teams should assess exposure and prioritize upgrading to version 3.45.0 or later. Restricting OpenAPI import access and monitoring for suspicious activity are also recommended.
Why it matters
CVE-2026-100680 is a high-severity vulnerability in Budibase server versions before 3.45.0, allowing authenticated builders to read arbitrary local files via OpenAPI import. Defenders should prioritize upgrading to version 3.45.0 or later, restricting OpenAPI import access, and monitoring for suspicious activity. The vulnerability's impact is supported by the CVE record and source item, but actual exploitation and victim organizations are not reported.
- Potential exfiltration of sensitive files, including environment variables with JWT secrets, API keys, and database credentials.
- Possible disruption of service due to unauthorized access to sensitive files.
- Need for verification of affected versions and exposure in specific deployment contexts.
- Priority for upgrading to version 3.45.0 or later and restricting OpenAPI import access.
Technical summary
Budibase server versions before 3.45.0 fail to disable external JSON reference resolution in the OpenAPI/Swagger import validator. This allows authenticated builders to read arbitrary local files by embedding file:// references in OpenAPI specifications submitted to the import endpoint. The vulnerability is caused by the lack of proper validation and sanitization of user-input data, which enables attackers to access sensitive files and data. The CVE record and source item provide details on the vulnerability, including affected versions and potential impacts.
Defensive priority
High priority for Budibase server administrators to upgrade to version 3.45.0 or later and restrict OpenAPI import access.
Recommended defensive actions
- Upgrade Budibase server to version 3.45.0 or later
- Restrict access to OpenAPI import functionality
- Monitor for suspicious activity related to OpenAPI imports
- Review and update environment variables and sensitive files
- Perform a thorough review of the system for any signs of exploitation
- Implement additional monitoring and logging to detect potential attacks
- Conduct a comprehensive risk assessment to identify potential vulnerabilities
Evidence notes
The CVE record and source item provide details on the vulnerability, including affected versions and potential impacts. However, limited information is available on actual exploitation or victim organizations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-100680 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-100680
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-100680 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100680
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Budibase before 3.45.0 Arbitrary Local File Read via OpenAPI Import
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/100xxx/CVE-2026-100680.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/Budibase/budibase/security/advisories/GHSA-8xr5-pggf-26jq
Supplemental source - vendor-advisory
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/budibase-before-3.45.0-arbitrary-local-file-read-via-openapi-import
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.