Skip to content

Known CVE

Budibase - Authentication Bypass

Budibase <= 3.31.4 contains an authentication bypass caused by unanchored regex in authorized() middleware matching webhook path patterns in query strings, letting unauthenticated remote attackers access any server-side API endpoint, exploit requires crafted request with webhook pattern in URL.

CVE-2026-31816

Critical2026CVSS 9.1CWE-74

cve2026 · budibase · auth-bypass · vuln · unauthenticated · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website