CVSS
7.7
CVSS v3.1
EPSS
N/A
Exploit Prediction Score
Published
August 13, 2026
Exploitability
No EPSS data available
Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowing authenticated users to read MongoDB connection strings and Firebase private keys in plaintext. Attackers with table read permissions can retrieve datasource configurations through the read API to obtain live backend database credentials and service account keys.
No package data available.
Publisher and database URLs for this record (shown for attribution; reading stays in Bugflare).