Budibase - Authentication Bypass
CVE-2026-31816
Verified
Description
Budibase <= 3.31.4 contains an authentication bypass caused by unanchored regex in authorized() middleware matching webhook path patterns in query strings, letting unauthenticated remote attackers access any server-side API endpoint, exploit requires crafted request with webhook pattern in URL.
Severity
Critical
CVSS Score
9.1
Exploit Probability
2%
Published Date
March 25, 2026
Template Author
theamanrawat
CVE-2026-31816.yaml
9.1Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVE ID:
cve-2026-31816
CWE ID:
cwe-74
Remediation Steps
Update to a version later than 3.31.4 or latest available version.