PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-73407 Budibase CVE debrief

Budibase, an open-source low-code platform, had a critical vulnerability prior to version 3.40.1. The RestIntegration._req function in packages/server/src/integrations/rest.ts improperly handled authentication headers, allowing an unauthenticated attacker to potentially obtain stored bearer, basic, or static-header credentials by supplying a malicious path to a PUBLIC POST /api/v2/queries/:queryId query. This issue has been fixed in version 3.40.1.

Vendor
Budibase
Product
Unknown
CVSS
CRITICAL 9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-12
Original CVE updated
2026-09-08
Advisory published
2026-08-12
Advisory updated
2026-09-08

Who should care

Defenders managing Budibase instances, especially those with publicly accessible query endpoints, should assess exposure and prioritize upgrading to version 3.40.1 or later. Systems using Budibase should be reviewed for exposure, and defenders should monitor for suspicious activity on Budibase instances.

Why it matters

CVE-2026-73407 allows potential credential exposure in Budibase instances prior to version 3.40.1. Defenders managing Budibase should assess exposure, prioritize upgrading, and monitor for suspicious activity.

  • Potential credential exposure for Budibase instances with publicly accessible query endpoints
  • Need for verification of affected scope and inventory of Budibase instances
  • Priority for upgrading to Budibase version 3.40.1 or later
  • Monitoring for suspicious activity on Budibase instances

Technical summary

The RestIntegration._req function in Budibase packages/server/src/integrations/rest.ts was vulnerable to improper handling of authentication headers. An unauthenticated attacker could supply a malicious path to a PUBLIC POST /api/v2/queries/:queryId query to potentially obtain stored credentials. This issue allows potential credential exposure in Budibase instances prior to version 3.40.1. Defenders managing Budibase should assess exposure, prioritize upgrading, and monitor for suspicious activity. The CVE record and NVD entry provide details on the vulnerability.

Defensive priority

Defenders should prioritize upgrading to Budibase version 3.40.1 or later to mitigate this vulnerability. Systems using Budibase should be reviewed for exposure, especially those with publicly accessible query endpoints.

Recommended defensive actions

  • Upgrade to Budibase version 3.40.1 or later
  • Review systems using Budibase for exposure, especially those with publicly accessible query endpoints
  • Monitor for suspicious activity on Budibase instances
  • Confirm whether affected Budibase instances exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. However, the exact scope of affected systems and the number of victims remain unknown. The Budibase security advisory provides information on the fix in version 3.40.1.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-73407 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-73407

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-73407 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73407

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.