No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 14 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowing authenticated users to read MongoDB connection strings and Firebase private keys in plaintext. Attackers with table read permissions can retrieve datasource configurations through the read API to obtain live backend database credentials and service account keys. | |
| Title | Budibase before 3.40.0 Credential Exposure via STRING Fields | |
| First Time appeared |
Budibase
Budibase budibase |
|
| Weaknesses | CWE-522 | |
| CPEs | cpe:2.3:a:budibase:budibase:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Budibase
Budibase budibase |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-14T16:12:55.091Z
Reserved: 2026-08-10T15:16:31.372Z
Link: CVE-2026-72857
Updated: 2026-08-14T16:12:49.527Z
Status : Received
Published: 2026-08-13T22:17:25.040
Modified: 2026-08-14T17:20:31.747
Link: CVE-2026-72857
No data.
OpenCVE Enrichment
Updated: 2026-08-14T01:45:07Z