CVE-2026-25737Disclosure(budibase / budibase)

LOWCVSS 9.0 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.24.0 and earlier, an arbitrary file upload vulnerability exists even though file extension restrictions are configured. The restriction is enforced only at the UI level. An attacker can bypass these restrictions and upload malicious files.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-602CWE-79CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • budibase

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
budibase

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-09: 4Technical Details · 2026-03-09: 403-09
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25737 Arbitrary File Upload Vulnerability in Budibase Platform Versions 3.24.0 and Earlier https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25737

    Post summary

    A new arbitrary file upload vulnerability (CVE‑2026‑25737) targeting Budibase Platform versions 3.24.0 and earlier has been disclosed on Vulmon, but no PoC, exploit code, or patch details are provided.

    0000040
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-25737: HIGH] Budibase low code platform's versions 3.24.0 and earlier have an arbitrary file upload vulnerability, allowing attackers to bypass restrictions and upload malicious files. #cybersecurity#cve,CVE-2026-25737,#cybersecurity https://cvefind.com/CVE-2026-25737

    Post summary

    Budibase low code platform versions 3.24.0 and earlier are exposed to an arbitrary file upload vulnerability that can be exploited to upload malicious files.

    0000035
    600 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-25737 - High Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.24.0 and earlier, an arbitrary file upload vulnerability exists even though file extension restr... https://www.thehackerwire.com/vulnerability/CVE-2026-25737/ https://t.co/FhA0z9riRX

    Post summary

    The post announces CVE-2026-25737, a high severity arbitrary file upload flaw in Budibase <=3.24.0, but offers no PoC, exploit code, patch, or evidence of active exploitation.

    0000030
    129 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25737 Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.24.0 and earlier, an arbitrary file upload vulnerability exists even th… https://www.cve.org/CVERecord?id=CVE-2026-25737

    Post summary

    A low code platform Budibase 3.24.0 and earlier is affected by an arbitrary file upload vulnerability, disclosed under CVE-2026-25737.

    0000079
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbudibasebudibase---

Explore more