Budibase server

Published Atomicorp research notes for CVEs affecting Budibase server where WAF protections were observed during testing or engineering review.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

CVEVulnerabilityCVSSSeverityRules Observed
CVE-2026-72850Budibase before 3.40.0 Arbitrary File Write via Path Traversal9.4 (v4.0)Critical340007 , 344360 , 347009 , 390709
CVE-2026-82244Budibase before 3.41.3 Remote Code Execution via Plugin eval()9.4 (v4.0)Critical340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390719 , 393655
CVE-2026-72851Budibase before 3.40.0 SQL Injection via Unauthenticated Webhook9.0 (v4.0)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122 , 390572
CVE-2026-72855Budibase before 3.40.0 DNS Rebinding SSRF via OpenAPI and REST8.4 (v4.0)High337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-82243Budibase Server before 3.41.3 SSRF with Credential Leakage8.3 (v4.0)High337109 , 337110 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2026-82241Budibase backend-core SSRF via incomplete default blacklist7.1 (v4.0)High337109 , 337110 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2026-82246Budibase Server before 3.41.3 SSRF via Query Import7.1 (v4.0)High337109 , 337110 , 344360 , 398021 , 398022