Sploitus

CVE-2026-73407

No indexed exploits for CVE-2026-73407 yet

Budibase is an open-source low-code platform. Prior to 3.40.1, RestIntegration._req in packages/server/src/integrations/rest.ts attached credentials from getAuthHeaders and defaultHeaders without requiring the final request destination to match the datasource origin. An unauthenticated caller of a PUBLIC POST /api/v2/queries/:queryId query could supply an absolute or parameterized path to an attacker-controlled host and receive the stored bearer, basic, or static-header credentials. This issue is fixed in version 3.40.1.

Affected products
Budibase
Fix
Available
CVSS 4.0
9.0 CRITICAL
EPSS
0.4% (35th percentile)
Weakness
CWE-22
NVD status
Received
Published
2026-08-12
CVE-2026-73407 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-73407 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-73407 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.