August 11, 2026

CVE Watchtower


← Back to CVE List

CVE-2026-35216NVD

Vulnerability Summary

Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) on the Budibase server by triggering an automation that contains a Bash step via the public webhook endpoint. No authentication is required to trigger the exploit. The process executes as root inside the container. This issue has been patched in version 3.33.4.
Severity Level
CRITICAL(9.0)
Published Date
Apr 3, 2026
Last Modified
Jul 24, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
11.98%Probability
Root Weakness (CWE)
The software constructs all or part of an OS command using externally-influenced input, but does not properly neutralize special elements.
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityHigh
Privileges RequiredNone
User InteractionNone
ScopeChanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh