---
id: CVE-2026-100681
title: >-
  Budibase before 3.45.0 contains an unauthenticated server-side request forgery
  and credential exfiltration vulnerability in the Microsoft Teams webhook
  endpoint that accepts forged Bot Framework activities with arbitrary
  serviceUrl value…
summary: >-
  Budibase before 3.45.0 contains an unauthenticated server-side request forgery
  and credential exfiltration vulnerability in the Microsoft Teams webhook
  endpoint that accepts forged Bot Framework activities with arbitrary
  serviceUrl value…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-918
vendor: budibase
product: server
affected:
  - server < 3.45.0
published: '2026-09-26'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T14:16:52.293'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-100681'
references:
  - url: >-
      https://github.com/Budibase/budibase/security/advisories/GHSA-942w-fccr-8r3c
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/budibase-before-3.45.0-ssrf-and-oauth-token-exfiltration-via-teams-webhook
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-26T13:33:20.909Z'
---

## Overview

Budibase before 3.45.0 contains an unauthenticated server-side request forgery and credential exfiltration vulnerability in the Microsoft Teams webhook endpoint that accepts forged Bot Framework activities with arbitrary serviceUrl values. Attackers can submit a crafted POST request to inject an attacker-controlled serviceUrl that is persisted and used for all subsequent bot replies, causing the server to send live Microsoft OAuth access tokens in Authorization headers to the attacker's host and enabling blind internal network access.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
