CVE-2026-73409EPSS p9.0%
CVE-2026-73409CVE-2026-73409
Description
Budibase is an open-source low-code platform. Prior to 3.40.1, packages/server/src/integrations/mongodb.ts passed builder-controlled tlsCertificateKeyFile and tlsCAFile values directly to MongoClient on Budibase Cloud. A builder could submit absolute server paths through /api/datasources/verify and distinguish readable existing files from missing files by comparing the driver error, exposing a filesystem existence and readability oracle on the shared server. This issue is fixed in version 3.40.1.
Scoring
| EPSS | 0.19% probability of exploitation · percentile 9.0% · 2026-08-13T12:03:51Z |
| Last modified | 2026-08-12 |