CVE-2026-35216
High
High exploit probability or critical severity with a known exploit.
CVSS base
9.0
CRITICAL
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
10.7%
95.6th percentile
CISA KEV
Not listed
Weakness / dates
CWE-78
Published 2026-04-03 · modified 2026-07-24
Description
Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) on the Budibase server by triggering an automation that contains a Bash step via the public webhook endpoint. No authentication is required to trigger the exploit. The process executes as root inside the container. This issue has been patched in version 3.33.4.
Affected
References
- https://github.com/Budibase/budibase/commit/f0c731b409a96e401445a6a6030d2994ff4ac256
- https://github.com/Budibase/budibase/pull/18238
- https://github.com/Budibase/budibase/releases/tag/3.33.4
- exploit https://github.com/Budibase/budibase/security/advisories/GHSA-fcm4-4pj2-m5hf
- exploit https://github.com/Budibase/budibase/security/advisories/GHSA-fcm4-4pj2-m5hf