CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-100681: server 0 to before 3.45.0

CVE-2026-100681. CVSS 3.1 base score 5.4 (MEDIUM, Vendor/CNA). EPSS 0.00249 (percentile 0.14832), scored 2026-10-06.

Affected technology

server · 0 to before 3.45.0
budibase

Description’s affected range: before 3.45.0

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · No privileges required · No user interaction required

What an attacker can do

Attackers can submit a crafted POST request to inject an attacker-controlled serviceUrl that is persisted and used for all subsequent bot replies, causing the server to send live Microsoft OAuth access tokens in Authorization headers to the attacker's host and enabling blind internal network access. Vendor/CNA’s CVSS 4.0 assessment (base score 6.3/10) rates confidentiality and integrity impact as low; availability impact as none.

Published

CWE
CWE-918
CCR priority
21.7 /100 (P4)
CVSS 3.1
5.4 /10 · CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N · Vendor/CNA
EPSS
0.00249 · percentile 0.14897 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-100681.html