{"id":"CVE-2026-33226","title":"Budibase is a low code platform for creating internal tools, workflows, and admin panels","summary":"Budibase is a low code platform for creating internal tools, workflows, and admin panels. In versions from 3.30.6 and prior, the REST datasource query preview endpoint (POST /api/queries/preview) makes server-side HTTP requests to any UR…","severity":"high","cvss":8.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N","cwe":["CWE-918"],"vendor":"budibase","product":"budibase","affected":["budibase <= 3.30.6"],"published":"2026-03-20","updated":"2026-10-07","sourceUpdated":"2026-10-07T08:10:00.200","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-33226","references":[{"url":"https://github.com/Budibase/budibase/security/advisories/GHSA-4647-wpjq-hh7f","label":"security-advisories@github.com"}],"tags":["nvd"],"epss":0.004,"epssPercentile":0.31986,"ingestedAt":"2026-10-07T08:20:03.903Z","slug":"CVE-2026-33226","body":"## Overview\n\nBudibase is a low code platform for creating internal tools, workflows, and admin panels. In versions from 3.30.6 and prior, the REST datasource query preview endpoint (POST /api/queries/preview) makes server-side HTTP requests to any URL supplied by the user in fields.path with no validation. An authenticated admin can reach internal services that are not exposed to the internet — including cloud metadata endpoints (AWS/GCP/Azure), internal databases, Kubernetes APIs, and other pods on the internal network. On GCP this leads to OAuth2 token theft with cloud-platform scope (full GCP access). On any deployment it enables full internal network enumeration. At time of publication, there are no publicly available patches.\n\n## Affected\n\n- `budibase <= 3.30.6`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":47.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}