CVE-2026-30240Disclosure(budibase / budibase)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch budibase budibase systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.5 and earlier, a path traversal vulnerability in the PWA (Progressive Web App) ZIP processing endpoint (POST /api/pwa/process-zip) allows an authenticated user with builder privileges to read arbitrary files from the server filesystem, including /proc/1/environ which contains all environment variables — JWT secrets, database credentials, encryption keys, and API tokens. The server reads attacker-specified files via unsanitized path.join() with user-controlled input from icons.json inside the uploaded ZIP, then uploads the file contents to the object store (MinIO/S3) where they can be retrieved through signed URLs. This results in complete platform compromise as all cryptographic secrets and service credentials are exfiltrated in a single request.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-73

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • budibase

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • Peaked 3d ago at 3 mentions (2026-03-09); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
budibase

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-03-09: 3Mentions · 2026-03-10: 1Mentions · 2026-03-16: 1Mentions · 2026-06-23: 1Patch / Workaround · 2026-03-09: 1Patch / Workaround · 2026-03-10: 1Technical Details · 2026-03-09: 3Technical Details · 2026-03-10: 1Technical Details · 2026-03-16: 1Technical Details · 2026-06-23: 103-0903-1003-1606-23
Signal classification2 categories
Disclosure
466.7%
Patch
233.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-093
Disclosure2Patch1
2026-03-101
Patch1
2026-03-161
Disclosure1
2026-06-231
Disclosure1
Full discourse6 posts
  • Gray Hats@the_yellow_fall
    Patch

    Two critical flaws in Budibase (CVE-2026-31816, CVE-2026-30240) allow unauthenticated API access and secret exfiltration via path traversal. Patch immediately. https://securityonline.info/total-platform-compromise-critical-9-6-cvss-flaws-in-budibase-expose-production-secrets/ https://t.co/wQZGgJOhdC

    Post summary

    Two critical Budibase CVEs (CVE‑2026‑31816, CVE‑2026‑30240) enable unauthenticated API access and secret exfiltration via path traversal; administrators are urged to apply patches immediately.

    02040357
    10.6K followersView on X
  • Chris@theshodandork
    Disclosure

    The auth bypass (CVE-2026-31816) works by appending "?/webhooks/trigger" to a Budibase API endpoint, an un-anchored regex in the server middleware matches this in the query string and skips all auth checks. The path traversal payloads (CVE-2026-30240) are crafted ZIP files containing icons.json with paths like "../../../../proc/1/environ", targeting the PWA upload endpoint to read server environment variables, which in Budibase deployments will possibly include database credentials, JWT secrets, and API keys.

    Post summary

    The passage discloses the exploitation techniques for CVE-2026-31816 and CVE-2026-30240, describing an authentication bypass and a path traversal, but does not provide PoC code, patches, or evidence of active exploitation.

    1000093
    9 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Budibase PWA ZIP Processing Path Traversal via Symlink, #CVE-2026-30240 (Critical) -DC-Jun2026-570 https://dailycve.com/budibase-pwa-zip-processing-path-traversal-via-symlink-cve-2026-30240-critical-dc-jun2026-570/

    Post summary

    The post announces CVE-2026-30240, a critical path traversal vulnerability via symlink in Budibase PWA ZIP processing.

    0000073
    216 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-30240: CRITICAL] Warning: Budibase's version 3.31.5 and earlier has a critical vulnerability allowing an attacker to access sensitive server files. Update to prevent cyber threats.#cve,CVE-2026-30240,#cybersecurity https://cvefind.com/CVE-2026-30240

    Post summary

    The tweet announces a critical vulnerability in Budibase versions <=3.31.5 that permits attackers to read sensitive server files and urges users to update to mitigate the risk.

    0000043
    600 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-30240 Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.5 and earlier, a path traversal vulnerability in the PWA (Progressiv… https://www.cve.org/CVERecord?id=CVE-2026-30240

    Post summary

    The snippet announces CVE-2026-30240, a path traversal flaw affecting Budibase PWA versions 3.31.5 and earlier, providing only technical detail without any exploit, patch, or reporting of active attacks.

    0000078
    56.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-30240 - Critical Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.5 and earlier, a path traversal vulnerability in the PWA (Progressive Web App) ZIP proces... https://www.thehackerwire.com/vulnerability/CVE-2026-30240/ https://t.co/CCRHgioCun

    Post summary

    The tweet announces a critical path traversal flaw in Budibase versions 3.31.5 and earlier, linking to an article for details.

    0000039
    129 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbudibasebudibase---

Explore more