CVE-2026-82246 UNKNOWN

CVE-2026-82246

Published: 2026-08-28

Description

Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the query import endpoint that fails to validate user-supplied URLs before fetching content. Attackers can submit arbitrary URLs to retrieve responses from internal services including cloud metadata endpoints and other restricted network resources.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…