CVE-2026-35216Disclosure(budibase / budibase)

LOWCVSS 9.0 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch budibase budibase systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) on the Budibase server by triggering an automation that contains a Bash step via the public webhook endpoint. No authentication is required to trigger the exploit. The process executes as root inside the container. This issue has been patched in version 3.33.4.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • budibase

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 3 mentions (2026-04-03); latest day: 2
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
budibase

Deep dive

Activity timeline7 mentions / 3d
01223Mentions · 2026-04-03: 3Mentions · 2026-04-04: 2Mentions · 2026-04-06: 2PoC Mentioned / Linked · 2026-04-06: 1Patch / Workaround · 2026-04-03: 1Patch / Workaround · 2026-04-06: 1Technical Details · 2026-04-03: 3Technical Details · 2026-04-04: 2Technical Details · 2026-04-06: 204-0304-0404-06
Signal classification2 categories
Disclosure
571.4%
Patch
228.6%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-033
Disclosure2Patch1
2026-04-042
Disclosure2
2026-04-062
Disclosure1Patch1
Full discourse7 posts
  • PulsePatch.io@pulsepatchio
    Disclosure

    Affected product: `Budibase`. Unauthenticated RCE possible via webhook and Bash automation. CVE-2026-35216. Review configurations. #RCE #infosec #DevSecOps https://www.pulsepatch.io/posts/cve-2026-35216-budibase-unauthenticated-rce

    Post summary

    The message announces a new unauthenticated RCE vulnerability (CVE-2026-35216) in Budibase that can be triggered via webhooks and Bash automation, but no PoC, exploit, or patch is provided.

    0000158
    11 followersView on X
  • Vulert@vulert_official
    Patch

    🚨 Critical Budibase flaw: CVE-2026-35216 A misconfigured webhook trigger could allow unauthenticated remote code execution in self-hosted deployments. Update immediately. 🔗 https://vulert.com/vuln-db/CVE-2026-35216 #CyberSecurity #Budibase #CVE202635216 #Vulert https://t.co/MTOpdmCXjP

    Post summary

    The tweet alerts users to a critical misconfiguration in Budibase that permits unauthenticated RCE and urges immediate updates of self-hosted deployments.

    0000039
    124 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    🚨🚨🚨 『No authentication is required to trigger the exploit. The process executes as root inside the container.』 CVE-2026-35216 Budibase Unauthenticated Remote Code Execution via Webhook Trigger and Bash Automation Step https://github.com/Budibase/budibase/security/advisories/GHSA-fcm4-4pj2-m5hf

    Post summary

    The advisory announces an unauthenticated remote code execution vulnerability in Budibase’s webhook trigger and bash automation, providing a link to the official GitHub advisory but detailing no exploitation code, active attacks, or patch information.

    00000393
    6.8K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-35216 - Critical Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) on the Budibase server by triggering an automati... https://www.thehackerwire.com/vulnerability/CVE-2026-35216/ https://t.co/sIV5o8rEOf

    Post summary

    The post announces CVE-2026-35216, which allows unauthenticated remote code execution on Budibase servers before v3.33.4, providing vulnerability specifics but no PoC, exploit code, patch, or evidence of active exploitation.

    0000059
    164 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-35216: CRITICAL] Budibase, an open-source low-code platform, fixed a critical security vulnerability in version 3.33.4 that allowed unauthenticated RCE by triggering a Bash step via a public webhoo...#cve,CVE-2026-35216,#cybersecurity https://cvefind.com/CVE-2026-35216

    Post summary

    Budibase released patch 3.33.4 to fix an unauthenticated remote code execution flaw triggered through a public webhook, confirming the vulnerability is remediated.

    0000050
    617 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35216 Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) on the Budibase server by t… https://www.cve.org/CVERecord?id=CVE-2026-35216

    Post summary

    The post announces CVE-2026-35216, exposing a Remote Code Execution flaw in Budibase versions earlier than 3.33.4, without mentioning an exploit, patch, or active use.

    0000055
    56.9K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-35216: Budib... Webhook-to-bash automation chain = instant root RCE without auth - low-code platforms becoming high-impact attack vectors #RCE #webhook #budibase. https://zerodaysignal.com/vulnerability/CVE-2026-35216 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑35216 against Budibase, describing an authentication‑free root RCE via a webhook‑to‑bash chain, with no PoC, exploit code, or patch mentioned.

    0000064
    197 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbudibasebudibase---

Explore more