{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/backend-core/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-82241"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["backend-core","server"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Budibase"],"content_html":"\u003cp\u003eCVE-2026-82241 identifies an SSRF vulnerability within the Budibase backend-core library, which is a component of the Budibase server. The vulnerability stems from an incomplete blacklist configuration that fails to account for the CGNAT address range 100.64.0.0/10. When an administrator has not manually configured a custom \u003ccode\u003eBLACKLIST_IPS\u003c/code\u003e list, the application defaults to an inadequate set of restricted addresses.\u003c/p\u003e\n\u003cp\u003eAn authenticated attacker with 'Builder' permissions can exploit this by interacting with the \u003ccode\u003ePOST /api/queries/preview\u003c/code\u003e endpoint. By submitting a crafted REST datasource query preview request, the attacker can force the Budibase server to perform an HTTP(S) request to arbitrary services within the 100.64.0.0/10 range. Because the preview functionality returns the response content to the user, this allows for sensitive data exfiltration or internal network reconnaissance. There is currently no vendor patch; the remediation requires manual configuration of the blacklist.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains access to a Budibase instance with 'Builder' level permissions.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the REST datasource management interface to configure a new query.\u003c/li\u003e\n\u003cli\u003eAttacker identifies a target service residing within the internal 100.64.0.0/10 CGNAT range.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a HTTP POST request to the \u003ccode\u003e/api/queries/preview\u003c/code\u003e endpoint with the target URL in the query body.\u003c/li\u003e\n\u003cli\u003eThe Budibase server fails to validate the target URL against the restricted 100.64.0.0/10 range.\u003c/li\u003e\n\u003cli\u003eThe backend server initiates an outbound request to the target internal service.\u003c/li\u003e\n\u003cli\u003eThe internal service responds to the server request.\u003c/li\u003e\n\u003cli\u003eThe Budibase server serializes the internal response and returns the data to the attacker via the UI/preview flow.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for unauthorized interaction with internal HTTP services that are intended to be protected from public or user-level access. This can lead to the exfiltration of sensitive information, unauthorized modification of internal state, or reconnaissance of the internal network architecture.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the Budibase \u003ccode\u003eBLACKLIST_IPS\u003c/code\u003e environment variable to include the 100.64.0.0/10 range as specified in the advisory for CVE-2026-82241.\u003c/li\u003e\n\u003cli\u003eMonitor access logs for \u003ccode\u003ePOST\u003c/code\u003e requests to \u003ccode\u003e/api/queries/preview\u003c/code\u003e to identify potential abuse of the datasource preview feature by users with 'Builder' permissions.\u003c/li\u003e\n\u003cli\u003eRestrict administrative 'Builder' access to only trusted personnel to mitigate the risk of account-based exploitation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T13:14:02Z","date_published":"2026-08-28T13:14:02Z","id":"https://feed.craftedsignal.io/briefs/2026-08-budibase-ssrf/","summary":"An SSRF vulnerability in Budibase backend-core allows authenticated users to bypass blacklist restrictions and perform requests against internal services in the 100.64.0.0/10 address range.","title":"CVE-2026-82241 SSRF Vulnerability in Budibase REST Datasource Preview","url":"https://feed.craftedsignal.io/briefs/2026-08-budibase-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Backend-Core","version":"https://jsonfeed.org/version/1.1"}