CVE-2026-31816 is an authentication bypass vulnerability in Budibase affecting version 3.31.4 and earlier. The flaw is in the server-side authorized() middleware that protects API endpoints. Budibase uses an isWebhookEndpoint() check that applies an unanchored regular expression to ctx.request.url; in Koa this value includes the full request URL including query parameters. Because of this, an attacker can append a webhook-style path fragment such as ?/webhooks/trigger to the query string of a request to a protected server-side API endpoint. If the regex matches that query content, the authorized() middleware immediately returns next(), skipping authentication, authorization, role enforcement, and CSRF checks. As a result, protected API routes can be reached without valid credentials.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a README and a single Python exploit script. The exploit targets Budibase CVE-2026-31816, an authentication/authorization bypass caused by matching webhook substrings against the full request URL including the query string. The script is a standalone Python tool, not tied to a major exploit framework. Its workflow is two-stage: first it checks whether a target Budibase instance can be accessed without authentication by appending ?/webhooks/trigger to a protected endpoint such as /api/integrations; if successful, it proceeds to build and upload a malicious plugin to /api/plugin/upload. The uploaded plugin contains JavaScript that calls child_process.exec() with a generated reverse-shell command. Supported payload styles include bash, python, netcat, and PowerShell. The script also supports operational features such as retries, proxying, SSL verification control, multiple targets, delays, and an optional listener to catch the reverse shell. Overall, this is a real operational exploit that combines unauthenticated API access with plugin-upload-based RCE against vulnerable Budibase deployments.
Repository contains a single Python exploit script and a README. - Files: - `CVE-2026-31816-rshell.py`: Standalone Python3 exploit that targets Budibase CVE-2026-31816. It implements an authentication-bypass URL construction by appending `?/webhooks/trigger` (or `&/webhooks/trigger`) to API endpoints. It first checks exposure by requesting `GET /api/integrations?/webhooks/trigger` and treating HTTP 200 as vulnerable. - `README.md`: Usage and explanation of the attack chain. - Exploit flow/capabilities: 1) Network-based auth bypass check against the Budibase API. 2) Builds a malicious Budibase DATASOURCE plugin as a `tar.gz` containing `package.json`, `schema.json`, and a Node.js module (`datasource-helper.js`). 3) The embedded JS payload uses `require('child_process').exec()` to run a bash reverse shell using `/dev/tcp` back to the operator-supplied `--lhost/--lport`. 4) Uploads the archive to `POST /api/plugin/upload?/webhooks/trigger`. The README indicates code execution occurs during plugin validation/installation. 5) Cleans up the local archive after attempting upload. - Notable observables: - HTTP endpoints: `/api/integrations` and `/api/plugin/upload` with the `?/webhooks/trigger` bypass suffix. - Reverse shell behavior: outbound TCP connection from target to attacker `lhost:lport`. Overall purpose: achieve unauthenticated remote code execution on a vulnerable Budibase server by abusing an auth bypass to upload a server-executed datasource plugin, resulting in a reverse shell.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Budibase vulnerability referenced briefly without technical detail.
An authentication bypass vulnerability in Budibase caused by improper regex validation in authorization middleware, allowing unauthorized access to protected functionality via a crafted ?/webhooks/trigger path.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.