---
id: CVE-2026-33226
title: >-
  Budibase is a low code platform for creating internal tools, workflows, and
  admin panels
summary: >-
  Budibase is a low code platform for creating internal tools, workflows, and
  admin panels. In versions from 3.30.6 and prior, the REST datasource query
  preview endpoint (POST /api/queries/preview) makes server-side HTTP requests
  to any UR…
severity: high
cvss: 8.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N'
cwe:
  - CWE-918
vendor: budibase
product: budibase
affected:
  - budibase <= 3.30.6
published: '2026-03-20'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T08:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-33226'
references:
  - url: >-
      https://github.com/Budibase/budibase/security/advisories/GHSA-4647-wpjq-hh7f
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.004
epssPercentile: 0.31986
ingestedAt: '2026-10-07T08:20:03.903Z'
---

## Overview

Budibase is a low code platform for creating internal tools, workflows, and admin panels. In versions from 3.30.6 and prior, the REST datasource query preview endpoint (POST /api/queries/preview) makes server-side HTTP requests to any URL supplied by the user in fields.path with no validation. An authenticated admin can reach internal services that are not exposed to the internet — including cloud metadata endpoints (AWS/GCP/Azure), internal databases, Kubernetes APIs, and other pods on the internal network. On GCP this leads to OAuth2 token theft with cloud-platform scope (full GCP access). On any deployment it enables full internal network enumeration. At time of publication, there are no publicly available patches.

## Affected

- `budibase <= 3.30.6`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
