A vulnerability classified as critical has been found in Budibase up to 3.39.x. Affected is an unknown function of the component OpenAPI Query Import. The manipulation leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2026-72855. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.