Chris[verified]@theshodandorkDisclosure
The passage discloses the exploitation techniques for CVE-2026-31816 and CVE-2026-30240, describing an authentication bypass and a path traversal, but does not provide PoC code, patches, or evidence of active exploitation.
Gray Hats@the_yellow_fallPatch
Two critical Budibase CVEs (CVE‑2026‑31816, CVE‑2026‑30240) enable unauthenticated API access and secret exfiltration via path traversal; administrators are urged to apply patches immediately.
DailyCVE@dailycveDisclosure
The post announces CVE-2026-30240, a critical path traversal vulnerability via symlink in Budibase PWA ZIP processing.
CVEFind.com@CveFindComPatch
The tweet announces a critical vulnerability in Budibase versions <=3.31.5 that permits attackers to read sensitive server files and urges users to update to mitigate the risk.
CVE@CVEnewDisclosure
The snippet announces CVE-2026-30240, a path traversal flaw affecting Budibase PWA versions 3.31.5 and earlier, providing only technical detail without any exploit, patch, or reporting of active attacks.
The Hacker Wire@TheHackerWireDisclosure
The tweet announces a critical path traversal flaw in Budibase versions 3.31.5 and earlier, linking to an article for details.