CVE-CVE-2026-31816
Severity
CRITICAL
CVSS Score
9.1
Description
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.4 and earlier, the Budibase server's authorized() middleware that protects every server-side API endpoint can be completely bypassed by appending a webhook path pattern to the query string of any request. The isWebhookEndpoint() function uses an unanchored regex that tests against ctx.request.url, which in Koa includes the full URL with query parameters. When the regex matches, the authorized() midd...
PoCs for CVE-CVE-2026-31816
CVE-2026-31816
RCE
Python
0
K3ysTr0K3R
2026-08-14