CVE-2026-100687: Budibase Server before 3.45.0 Credential Exposure via External Table Broadcast
Budibase Server before 3.45.0 fails to redact plaintext datasource credentials before broadcasting external table updates to the Builder collaboration websocket room. Attackers with Builder access can intercept unredacted datasource objects containing database passwords and API keys by observing table save or delete operations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Budibase Serverto a version that resolves this vulnerability.Fixed in 3.45.0
Event History
Frequently Asked Questions
Who can access the exposed credentials?
An attacker needs Builder access to observe the Builder collaboration websocket room. The vulnerability has high privilege requirements and does not describe exposure to unauthenticated users.
When are credentials broadcast?
Unredacted datasource objects can be broadcast during external table save or delete operations. The exposed values may include database passwords and API keys.
What version should be deployed to address this issue?
Upgrade Budibase Server to version 3.45.0 or later. Versions before 3.45.0 are affected.