Budibase Server before 3.45.0 fails to redact plaintext datasource credentials before broadcasting external table updates to the Builder collaboration websocket room. Attackers with Builder access can intercept unredacted datasource objects containing database passwords and API keys by observing table save or delete operations.
Budibase Server before 3.45.0 Credential Exposure via External Table Broadcast
Problem type
Affected products
budibase
< 3.45.0 - AFFECTED
3.45.0 - UNAFFECTED
References
https://github.com/Budibase/budibase/security/advisories/GHSA-rmv5-3xpj-w885
https://www.vulncheck.com/advisories/budibase-server-before-3.45.0-credential-exposure-via-external-table-broadcast
GitHub Security Advisories
GHSA-qhcg-hgqm-ww52
Budibase Server before 3.45.0 fails to redact plaintext datasource credentials before...
https://github.com/advisories/GHSA-qhcg-hgqm-ww52Budibase Server before 3.45.0 fails to redact plaintext datasource credentials before broadcasting external table updates to the Builder collaboration websocket room. Attackers with Builder access can intercept unredacted datasource objects containing database passwords and API keys by observing table save or delete operations.
https://github.com/Budibase/budibase/security/advisories/GHSA-rmv5-3xpj-w885
https://nvd.nist.gov/vuln/detail/CVE-2026-100687
https://www.vulncheck.com/advisories/budibase-server-before-3.45.0-credential-exposure-via-external-table-broadcast
https://github.com/advisories/GHSA-qhcg-hgqm-ww52
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-100687Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-100687",
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"dateUpdated": "2026-09-26T13:23:47.369Z",
"dateReserved": "2026-09-26T02:37:41.037Z",
"datePublished": "2026-09-26T13:23:47.369Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck",
"dateUpdated": "2026-09-26T13:23:47.369Z"
},
"datePublic": "2026-09-10T00:00:00.000Z",
"title": "Budibase Server before 3.45.0 Credential Exposure via External Table Broadcast",
"descriptions": [
{
"lang": "en",
"value": "Budibase Server before 3.45.0 fails to redact plaintext datasource credentials before broadcasting external table updates to the Builder collaboration websocket room. Attackers with Builder access can intercept unredacted datasource objects containing database passwords and API keys by observing table save or delete operations."
}
],
"affected": [
{
"vendor": "budibase",
"product": "server",
"defaultStatus": "unaffected",
"versions": [
{
"version": "0",
"status": "affected",
"versionType": "semver",
"lessThan": "3.45.0"
},
{
"version": "3.45.0",
"status": "unaffected",
"versionType": "semver"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "Exposure of Sensitive Information to an Unauthorized Actor",
"cweId": "CWE-200",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://github.com/Budibase/budibase/security/advisories/GHSA-rmv5-3xpj-w885",
"name": "GitHub Security Advisory (GHSA-rmv5-3xpj-w885)",
"tags": [
"vendor-advisory"
]
},
{
"url": "https://www.vulncheck.com/advisories/budibase-server-before-3.45.0-credential-exposure-via-external-table-broadcast",
"name": "VulnCheck Advisory: Budibase Server before 3.45.0 Credential Exposure via External Table Broadcast",
"tags": [
"third-party-advisory"
]
}
],
"metrics": [
{
"format": "CVSS"
},
{
"format": "CVSS",
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "HIGH",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "LOW",
"availabilityImpact": "NONE",
"baseScore": 5.5,
"baseSeverity": "MEDIUM"
}
}
],
"credits": [
{
"lang": "en",
"value": "iaohkut-from-NightWolf-Team",
"type": "reporter"
}
]
}
}
}