Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowing authenticated users to read MongoDB connection strings and Firebase private keys in plaintext. Attackers with table read permissions can retrieve datasource configurations through the read API to obtain live backend database credentials and service account keys.
Metrics
Affected Vendors & Products
References
History
Fri, 14 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowing authenticated users to read MongoDB connection strings and Firebase private keys in plaintext. Attackers with table read permissions can retrieve datasource configurations through the read API to obtain live backend database credentials and service account keys. | |
| Title | Budibase before 3.40.0 Credential Exposure via STRING Fields | |
| First Time appeared |
Budibase
Budibase budibase |
|
| Weaknesses | CWE-522 | |
| CPEs | cpe:2.3:a:budibase:budibase:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Budibase
Budibase budibase |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-14T16:12:55.091Z
Reserved: 2026-08-10T15:16:31.372Z
Link: CVE-2026-72857
Updated: 2026-08-14T16:12:49.527Z
Status : Received
Published: 2026-08-13T22:17:25.040
Modified: 2026-08-14T17:20:31.747
Link: CVE-2026-72857
No data.
OpenCVE Enrichment
Updated: 2026-08-14T01:45:07Z