CVE-2026-31816 is a critical authentication bypass vulnerability affecting Budibase versions 3.31.4 and earlier, a low-code platform for internal tools. Rated 9.1 CRITICAL, this flaw allows an unauthenticated, remote attacker to completely bypass server-side API endpoint protection by appending a specific webhook pattern to any request URL. This enables full access to sensitive data and system functionality, compromising confidentiality and integrity without requiring user interaction. Although not on the KEV or Hot List, and public exploit code is not available in common databases like Metasploit or Nuclei, the vulnerability has generated some community discussion regarding its exploitability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.31.4CPE matchmatch criteria | cpe:2.3:a:budibase:budibase:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.