AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-72850

CRITICAL · CVSS 9.1 EPSS 0.42% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

Budibase versions prior to 3.40.0 are vulnerable due to improper sanitization of S3 object keys, enabling authenticated users to exploit directory traversal sequences. This flaw allows attackers to upload files that can overwrite arbitrary paths writable by the Budibase process, potentially leading to unauthorized data exposure or system compromise. Organizations using Budibase should prioritize patching to mitigate this critical risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-72850
Severity
CRITICAL
CVSS
9.1
EPSS
0.42%

Original NVD Description

Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are preserved during export. Attackers can craft filenames containing .. segments that escape the temporary directory during workspace export, writing arbitrary content to any path writable by the Budibase process.