PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72857 Budibase CVE debrief

Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowing authenticated users to read MongoDB connection strings and Firebase private keys in plaintext. Attackers with table read permissions can retrieve datasource configurations through the read API to obtain live backend database credentials and service account keys. This vulnerability affects Budibase users with versions before 3.40.0, administrators of Budibase instances, and security teams monitoring for credential exposure vulnerabilities. The vulnerability has a high CVSS score of 8.3, indicating a critical severity level. Budibase users should prioritize patching to version 3.40.0 or later and restrict API access to sensitive datasource configurations.

Vendor
Budibase
Product
Unknown
CVSS
HIGH 8.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-13
Original CVE updated
2026-08-31
Advisory published
2026-08-13
Advisory updated
2026-08-31

Who should care

Budibase users with versions before 3.40.0, administrators of Budibase instances, and security teams monitoring for credential exposure vulnerabilities should be aware of this vulnerability and take immediate action to patch or mitigate it. The vulnerability affects Budibase deployments where authenticated users have table read permissions, which can lead to unauthorized access to live backend database credentials and service account keys. Security teams should prioritize patching and restrict API access to sensitive datasource configurations to prevent exploitation. Additionally, Budibase users should review their current configurations and ensure that they are not exposing sensitive credentials to unauthorized users. This may involve reviewing user permissions, API access controls, and datasource configurations to prevent potential attacks. By taking these steps, Budibase users can help prevent the exploitation of this vulnerability and protect their sensitive credentials. It is also essential for security teams to monitor for potential attacks and implement compensating controls to detect and respond to potential security incidents. This may involve reviewing logs, monitoring for suspicious activity, and implementing additional security controls to prevent lateral movement in case of a breach. Overall, Budibase users and security teams should take a proactive approach to addressing this vulnerability and implement measures to prevent exploitation and protect sensitive credentials. This includes applying patches, restricting API access, and implementing additional security controls to prevent unauthorized access to sensitive credentials. By doing so, they can help prevent potential security incidents and protect their Budibase deployments from exploitation. The vulnerability highlights the importance of proper credential management and access controls in preventing unauthorized access to sensitive credentials. It also emphasizes the need for proactive vulnerability management and patching to prevent exploitation of known vulnerabilities. By prioritizing patching and implementing additional security controls, Budibase users can help protect their deployments. 7

Technical summary

Budibase before 3.40.0 stores datasource credentials in plaintext within STRING typed fields. Authenticated users with table read permissions can retrieve datasource configurations through the read API to obtain live backend database credentials and service account keys. This vulnerability is particularly concerning for Budibase users with versions before 3.40.0, as it allows attackers to access sensitive credentials with relative ease. The vulnerability can be mitigated by applying the Budibase patch version 3.40.0 or later and restricting read API access to sensitive datasource configurations.

Defensive priority

Authenticated users with table read permissions can access sensitive credentials; prioritize patching and restrict API access.

Recommended defensive actions

  • Apply Budibase patch version 3.40.0 or later
  • Restrict read API access to sensitive datasource configurations
  • Monitor for unauthorized access to backend database credentials and service account keys
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE description indicates Budibase versions before 3.40.0 store datasource credentials in plaintext within STRING typed fields. Authenticated users with table read permissions can exploit this vulnerability to obtain live backend database credentials and service account keys via the read API. Vendor patching and API access restrictions are recommended.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72857 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72857

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72857 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72857

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.