logo

Critical 9.1 Auth Bypass Hits Budibase Operations Platform

ID: 8c0b8b8c-125d-51df-9b59-259be91932d0

STIX ID: report--8c0b8b8c-125d-51df-9b59-259be91932d0

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-04-20

Date Updated: 2026-04-23

Author: Ddos

...
...

Budibase issued a high-priority security update to address a critical CVSS 9.1 authentication bypass where unanchored regex patterns in the authentication middleware allowed attackers to append public endpoint paths in query strings and gain unauthenticated access to protected administrative endpoints; the flaw enables full user enumeration and other administrative actions and is fixed in version 3.35.4 by anchoring regex patterns and switching to ctx.request.path.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.