CVE-2026-73407
Budibase is an open-source low-code platform. Prior to 3.40.1, RestIntegration._req in packages/server/src/integrations/rest.ts attached credentials from getAuthHeaders and defaultHeaders without requiring the final request destination to match the datasource origin. An unauthenticated caller of a PUBLIC POST /api/v2/queries/:queryId query could supply an absolute or parameterized path to an attacker-controlled host and receive the stored bearer, basic, or static-header credentials. This issue is fixed in version 3.40.1.
- Affected products
- Budibase
- Fix
- Available
- CVSS 4.0
- 9.0 CRITICAL
- EPSS
- 0.4% (35th percentile)
- Weakness
- CWE-22
- NVD status
- Received
- Published
- 2026-08-12
No indexed exploits for CVE-2026-73407 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-73407 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.