OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100680

HIGH · CVSS 8.1 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Budibase versions prior to 3.45.0 are vulnerable due to inadequate restrictions on external JSON reference resolution in the OpenAPI/Swagger import validator, enabling authenticated builders to access arbitrary local files. This flaw allows attackers with builder access to exfiltrate sensitive information such as JWT secrets, API keys, and database credentials by embedding file:// references in submitted OpenAPI specifications. Organizations using affected versions should prioritize patching to mitigate the risk of sensitive data exposure.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100680
Severity
HIGH
CVSS
8.1
EPSS
0.23%

Original NVD Description

Budibase versions before 3.45.0 fail to disable external JSON reference resolution in the OpenAPI/Swagger import validator, allowing authenticated builders to read arbitrary local files. Attackers with builder access can embed file:// references in OpenAPI specifications submitted to the import endpoint to exfiltrate sensitive files including environment variables containing JWT secrets, API keys, and database credentials.