---
cve: "CVE-2026-100681"
severity: "MEDIUM"
cvss: 6.3
epss: "0.3%"
vendor: "budibase"
kev: false
exploited: false
published: "2026-09-26 14:16:52"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-10-06T09:36:12+02:00"
---

# CVE-2026-100681

> 6.3 MEDIUM · 🧪 PoC

## Beschreibung

Budibase before 3.45.0 contains an unauthenticated server-side request forgery and credential exfiltration vulnerability in the Microsoft Teams webhook endpoint that accepts forged Bot Framework activities with arbitrary serviceUrl values. Attackers can submit a crafted POST request to inject an attacker-controlled serviceUrl that is persisted and used for all subsequent bot replies, causing the server to send live Microsoft OAuth access tokens in Authorization headers to the attacker's host and enabling blind internal network access.

## CNA-Record (Kanon, cvelistV5)

- CNA: **VulnCheck**
- State: PUBLISHED
- Stand: 2026-09-30 17:39:28
- CNA-CVSS: **6.3** (`CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N`)

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **poc**
  - Automatable: **no**
  - Technical Impact: **partial**

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Hoch | good |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |

## Patch verfügbar (OSV)

- 2790401d5070fd5f71145683034ef333699bf8d3 (Commit)

## BSI-Hinweise (deutsch)

- [Budibase: Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/sicherheitshinweis/WID-SEC-W-2026-3286) — _BSI-Einstufung: kritisch_
  Ein Angreifer kann mehrere Schwachstellen in Budibase ausnutzen, um erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, SQL-Injection-Angriffe durchzuführen oder Daten zu manipulieren und offenzulegen.

## Referenzen

- <https://github.com/Budibase/budibase/security/advisories/GHSA-942w-fccr-8r3c>
- <https://www.vulncheck.com/advisories/budibase-before-3.45.0-ssrf-and-oauth-token-exfiltration-via-teams-webhook>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-100681) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
