CVE-2026-35216

Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) on the Budibase server by triggering an automation that contains a Bash step via the public webhook endpoint. No authentication is required to trigger the exploit. The process executes as root inside the container. This issue has been patched in version 3.33.4.
Configurations

Configuration 1 (hide)

cpe:2.3:a:budibase:budibase:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-03 16:16

Updated : 2026-07-24 21:10


NVD link : CVE-2026-35216

Mitre link : CVE-2026-35216

CVE.ORG link : CVE-2026-35216


JSON object : View

Products Affected

budibase

  • budibase
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')