CVE-2026-82246: Budibase Server before 3.41.3 SSRF via Query Import

Published Aug 28, 2026
·
Updated

Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the query import endpoint that fails to validate user-supplied URLs before fetching content. Attackers can submit arbitrary URLs to retrieve responses from internal services including cloud metadata endpoints and other restricted network resources.

Affected Software

1 affected component
budibase Budibase Server<3.41.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Budibase Server to a version that resolves this vulnerability.

    Fixed in 3.41.3
  2. Compensating control

    Restrict network access from Budibase (especially the query import endpoint) to internal services and cloud metadata endpoints, so outbound requests to restricted network resources cannot be reached.

Event History

Aug 28, 2026
CVE Published
via MITRE·10:49 AM
Data Sourced
via MITRE·10:49 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are affected?

Budibase Server versions before 3.41.3 are affected. The issue is in the query import endpoint.

2

What access does an attacker need?

An attacker needs low-level authenticated privileges to submit a URL through the query import endpoint. No user interaction is required.

3

What could an attacker reach through this issue?

The attacker can cause the server to fetch arbitrary user-supplied URLs and retrieve responses. This can expose internal services, cloud metadata endpoints, and other network resources that are restricted from direct attacker access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203