CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-72855

highCVSS 8.5covered by 1 sourcefirst seen 2026-08-13
Budibase before 3.40.0 contains server-side request forgery vulnerabilities in OpenAPI query import and REST query execution that allow authenticated builder-level users to bypass DNS pinning protections through DNS rebinding attacks. Attackers can configure hostnames that resolve to public addresses during validation but resolve to loopback or private addresses during actual connection, allowing access to blocked internal HTTP services.

⚡ Watch CVE-2026-72855

Get an email if CVE-2026-72855 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-72855

CVE.org record

Embed the live status

CVE-2026-72855 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-72855 status](https://www.csirts.com/badge/CVE-2026-72855)](https://www.csirts.com/cve/CVE-2026-72855)