Known CVE
Budibase - Authentication Bypass
Budibase <= 3.31.4 contains an authentication bypass caused by unanchored regex in authorized() middleware matching webhook path patterns in query strings, letting unauthenticated remote attackers access any server-side API endpoint, exploit requires crafted request with webhook pattern in URL.
CVE-2026-31816
Critical2026CVSS 9.1CWE-74
cve2026 · budibase · auth-bypass · vuln · unauthenticated · vkev
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website