CVE-2026-35216
Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) on the Budibase server by triggering an automation that contains a Bash step via the public webhook endpoint.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.7%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) on the Budibase server by triggering an automation that contains a Bash step via the public webhook endpoint. No authentication is required to trigger the exploit. The process executes as root inside the container. This issue has been patched in version 3.33.4.
- CVSS 3.1
- 9.0 CRITICALCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 10.72% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- budibase/budibase
- Source
- security-advisories@github.com
References
- https://github.com/Budibase/budibase/commit/f0c731b409a96e401445a6a6030d2994ff4ac256Patch
- https://github.com/Budibase/budibase/pull/18238Issue Tracking, Patch
- https://github.com/Budibase/budibase/releases/tag/3.33.4Product, Release Notes
- https://github.com/Budibase/budibase/security/advisories/GHSA-fcm4-4pj2-m5hfExploit, Vendor Advisory
- https://github.com/Budibase/budibase/security/advisories/GHSA-fcm4-4pj2-m5hfExploit, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.