Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowing authenticated users to read MongoDB connection strings and Firebase private keys in plaintext. Attackers with table read permissions can retrieve datasource configurations through the read API to obtain live backend database credentials and service account keys.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 13 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowing authenticated users to read MongoDB connection strings and Firebase private keys in plaintext. Attackers with table read permissions can retrieve datasource configurations through the read API to obtain live backend database credentials and service account keys. | |
| Title | Budibase before 3.40.0 Credential Exposure via STRING Fields | |
| First Time appeared |
Budibase
Budibase budibase |
|
| Weaknesses | CWE-522 | |
| CPEs | cpe:2.3:a:budibase:budibase:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Budibase
Budibase budibase |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-13T21:54:45.984Z
Reserved: 2026-08-10T15:16:31.372Z
Link: CVE-2026-72857
No data.
Status : Received
Published: 2026-08-13T22:17:25.040
Modified: 2026-08-13T22:17:25.040
Link: CVE-2026-72857
No data.
OpenCVE Enrichment
No data.
Weaknesses