CVE-2026-100681 Overview
CVE-2026-100681 is an unauthenticated Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability in Budibase versions before 3.45.0. The flaw resides in the Microsoft Teams webhook endpoint, which accepts forged Bot Framework activities carrying arbitrary serviceUrl values. An attacker can submit a crafted POST request that injects an attacker-controlled serviceUrl. Budibase persists this value and uses it for all subsequent bot replies. The server then transmits live Microsoft OAuth access tokens in Authorization headers to the attacker-controlled host. The vulnerability is tracked as CWE-918: Server-Side Request Forgery.
Critical Impact
Unauthenticated attackers can exfiltrate live Microsoft OAuth access tokens and perform blind internal network requests from the Budibase server.
Affected Products
- Budibase versions prior to 3.45.0
- Deployments exposing the Microsoft Teams webhook integration endpoint
- Self-hosted and cloud Budibase instances using Bot Framework activity handling
Discovery Timeline
- 2026-09-26 - CVE-2026-100681 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-100681
Vulnerability Analysis
The vulnerability exists in the Microsoft Teams webhook integration within Budibase. The endpoint processes incoming Bot Framework activity objects without validating the embedded serviceUrl field. In the Bot Framework protocol, serviceUrl designates the host that the bot calls back to deliver reply activities.
Budibase trusts the attacker-supplied serviceUrl from the inbound activity, stores it, and uses it as the destination for all subsequent outbound replies. Because the endpoint requires no authentication, remote attackers can shape the server's outbound HTTP behavior with a single crafted POST request.
Root Cause
The root cause is missing validation and allowlisting of the serviceUrl parameter in received Bot Framework activities. Budibase assumes the field originates from a legitimate Microsoft endpoint. There is no verification that the URL resolves to a Microsoft-controlled host or matches an expected pattern before the value is persisted and reused for authenticated outbound requests.
Attack Vector
An unauthenticated attacker sends a forged Bot Framework activity to the Teams webhook endpoint with a serviceUrl pointing to an attacker-controlled host. Budibase stores this value and attaches a valid Microsoft OAuth access token to subsequent reply calls routed to that host. The attacker captures the bearer token from the inbound Authorization header. The attacker can also point serviceUrl at internal network addresses to probe systems that are unreachable from the public internet, achieving blind SSRF against the Budibase host's internal network. For full technical reproduction steps, see the VulnCheck SSRF Vulnerability Advisory and the GitHub Security Advisory.
Detection Methods for CVE-2026-100681
Indicators of Compromise
- Outbound HTTPS requests from the Budibase server to unknown or non-Microsoft hosts carrying Authorization: Bearer headers
- POST requests to the Microsoft Teams webhook endpoint from unexpected source IP addresses
- Persisted serviceUrl values in Budibase state that do not resolve to *.botframework.com or Microsoft-owned infrastructure
- Outbound connection attempts from Budibase to RFC1918 or link-local addresses originating from Teams integration logic
Detection Strategies
- Inspect reverse proxy and web server logs for POST requests to the Teams webhook route with external, non-Microsoft serviceUrl values in the JSON payload
- Correlate outbound egress logs with Budibase process activity to detect bearer token transmission to untrusted destinations
- Alert on any Budibase outbound HTTP traffic destined for internal subnets that are not part of normal application behavior
Monitoring Recommendations
- Enable verbose request logging on the Teams webhook endpoint, including full request bodies, during triage
- Monitor Microsoft Entra ID sign-in and token-usage telemetry for anomalous use of OAuth tokens issued to the Budibase bot application
- Track egress destinations from application servers and flag deviations from an approved allowlist of Microsoft Bot Framework endpoints
How to Mitigate CVE-2026-100681
Immediate Actions Required
- Upgrade all Budibase deployments to version 3.45.0 or later without delay
- Rotate any Microsoft OAuth client secrets, bot credentials, and access tokens associated with the Budibase Teams integration
- Review Entra ID audit logs for suspicious token use that predates the upgrade
- Restrict network egress from the Budibase server to known Microsoft Bot Framework hosts
Patch Information
Budibase addressed the vulnerability in release 3.45.0. The fix validates the serviceUrl field in inbound Bot Framework activities against expected Microsoft endpoints before the value is persisted or used for authenticated outbound calls. See the GitHub Security Advisory GHSA-942w-fccr-8r3c for release details.
Workarounds
- Disable the Microsoft Teams webhook integration until the upgrade to 3.45.0 can be applied
- Place the Budibase server behind an egress proxy that restricts outbound HTTPS to the official *.botframework.com domains
- Block unauthenticated inbound traffic to the Teams webhook route at the reverse proxy or Web Application Firewall layer
# Example egress allowlist enforcement (iptables, illustrative)
iptables -A OUTPUT -p tcp -d smba.trafficmanager.net --dport 443 -j ACCEPT
iptables -A OUTPUT -p tcp --dport 443 -m string --algo bm \
--string "botframework.com" -j ACCEPT
iptables -A OUTPUT -p tcp --dport 443 -j REJECT
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.