---
id: CVE-2026-100687
title: >-
  Budibase Server before 3.45.0 fails to redact plaintext datasource credentials
  before broadcasting external table updates to the Builder collaboration
  websocket room
summary: >-
  Budibase Server before 3.45.0 fails to redact plaintext datasource credentials
  before broadcasting external table updates to the Builder collaboration
  websocket room. Attackers with Builder access can intercept unredacted
  datasource obje…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N'
cwe:
  - CWE-200
vendor: budibase
product: server
affected:
  - server < 3.45.0
published: '2026-09-26'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T14:16:53.140'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-100687'
references:
  - url: >-
      https://github.com/Budibase/budibase/security/advisories/GHSA-rmv5-3xpj-w885
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/budibase-server-before-3.45.0-credential-exposure-via-external-table-broadcast
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-26T13:33:20.907Z'
---

## Overview

Budibase Server before 3.45.0 fails to redact plaintext datasource credentials before broadcasting external table updates to the Builder collaboration websocket room. Attackers with Builder access can intercept unredacted datasource objects containing database passwords and API keys by observing table save or delete operations.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
