OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100682

HIGH · CVSS 8.8 EPSS 0.57% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Budibase Server versions prior to 3.45.0 are vulnerable to an arbitrary file write flaw in the PWA icon upload endpoint, allowing attackers with a BUILDER role to exploit improperly validated symlink entries in user-supplied ZIP archives. This vulnerability can lead to remote code execution by enabling the writing of arbitrary files as root. Organizations using Budibase Server should prioritize patching to mitigate the risk of potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100682
Severity
HIGH
CVSS
8.8
EPSS
0.57%

Original NVD Description

Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon upload endpoint that extracts user-supplied ZIP archives without proper symlink validation. Attackers with BUILDER role can craft a malicious ZIP with leaf symlink entries followed by duplicate file entries to write arbitrary files as root, enabling remote code execution.