
CVE-2026-31816 - Budibase Authentication Bypass to RCE
CVE-2026-31816 is a critical authentication and authorization bypass vulnerability affecting Budibase.
The vulnerability exists in the server-side authorization middleware responsible for protecting API endpoints. Budibase attempts to identify legitimate webhook endpoints with an unanchored regular expression and evaluates that expression against Koa's ctx.request.url.
Because ctx.request.url contains the query string, an attacker can inject a webhook-looking path into the query component of an otherwise unrelated API request.
For example:
/api/integrations?/webhooks/trigger
The request does not actually target the webhook endpoint. However, the vulnerable check can interpret /webhooks/trigger as evidence that the request is a legitimate webhook request and allow execution to continue without normal authentication and authorization checks.
NVD describes the issue as allowing a completely unauthenticated remote attacker to access server-side API endpoints by appending a webhook path pattern to the URL.
| Field | Value |
|---|---|
| CVE | CVE-2026-31816 |
| Vendor | Budibase |
| Product | Budibase |
| Affected versions | <= 3.31.4 |
| Severity | Critical |
| CVSS v3.1 | 9.1 |
| CVSS Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| CWE | CWE-74 |
| Attack Vector | Network |
| Privileges Required | None |
| User Interaction | None |
| Authentication Required | No |
NVD records Budibase versions through 3.31.4 as affected and assigns a CVSS 3.1 score of 9.1.
The vulnerable logic is centered around the webhook detection performed before normal authorization.
The security advisory documents code conceptually equivalent to:
const WEBHOOK_ENDPOINTS = new RegExp(
[
"webhooks/trigger",
"webhooks/schema",
"webhooks/discord",
"webhooks/ms-teams"
].join("|")
)
export function isWebhookEndpoint(ctx) {
return WEBHOOK_ENDPOINTS.test(ctx.request.url)
}
The problem is the combination of two behaviors:
ctx.request.url contains the query string.That means the expression does not need to match the actual request path.
A request such as:
/api/some/protected/endpoint?/webhooks/trigger
still contains the string:
/webhooks/trigger
inside the URL being tested.
The authorization middleware subsequently treats the request as a webhook request and reaches the endpoint without performing the normal authorization flow.
The Budibase security advisory explicitly identifies this as the underlying flaw and notes that the bypass skips authentication, authorization, role checks, and CSRF protection.
A normal request to a protected API endpoint would be expected to pass through the authentication layer.
For example:
GET /api/integrations HTTP/1.1
Host: target.example
Connection: close
A vulnerable instance can instead be reached with the webhook query-string pattern:
GET /api/integrations?/webhooks/trigger HTTP/1.1
Host: target.example
Connection: close
The important part is:
?/webhooks/trigger
The endpoint itself has not changed:
/api/integrations
Only the query string has been modified.
The public Budibase advisory demonstrates this exact technique against /api/integrations and several other server-side endpoints.
A safe way to verify the authentication bypass in a controlled lab is to compare an ordinary request with the webhook-query variant.
GET /api/integrations HTTP/1.1
Host: 127.0.0.1:10000
Connection: close
GET /api/integrations?/webhooks/trigger HTTP/1.1
Host: 127.0.0.1:10000
Connection: close
The vulnerable server can process the second request without the authentication checks that would normally protect the endpoint.
A published PoC similarly uses:
/api/integrations?/webhooks/trigger
as a simple vulnerability check.
The following demonstrates the structure of an authenticated API request being transformed into an unauthenticated request by adding the webhook pattern.
POST /api/ta_users/search?/webhooks/trigger HTTP/1.1
Host: 127.0.0.1:10000
Content-Type: application/json
x-budibase-app-id: <TARGET_WORKSPACE_ID>
Connection: close
Content-Length: 12
{"query":{}}
The official Budibase advisory documents this endpoint as one of the affected API surfaces.
Other server-side endpoints documented as reachable through the same flaw include:
/api/tables
/api/datasources
/api/automations
/api/roles
/api/integrations
/api/views
/api/plugins
The key observation is that the vulnerability is not tied to one particular application resource. The affected authorization middleware sits in front of a broad set of server-side APIs.
The authentication bypass can become considerably more serious when combined with a sensitive API capable of accepting attacker-controlled functionality.
The PoC in this repository chains the vulnerability as follows:
┌─────────────────────────┐
│ Remote attacker │
└────────────┬────────────┘
│
│ ?/webhooks/trigger
▼
┌─────────────────────────┐
│ Budibase authorization │
│ middleware │
└────────────┬────────────┘
│
│ authentication bypass
▼
┌─────────────────────────┐
│ Protected server-side │
│ API endpoints │
└────────────┬────────────┘
│
│ plugin upload
▼
┌─────────────────────────┐
│ /api/plugin/upload │
└────────────┬────────────┘
│
│ crafted plugin
▼
┌─────────────────────────┐
│ Plugin JavaScript code │
│ execution │
└────────────┬────────────┘
│
▼
Code execution
/api/integrations, then builds a Budibase plugin archive and submits it through /api/plugin/upload.