PulsePatch.io@pulsepatchioDisclosure
The message announces a new unauthenticated RCE vulnerability (CVE-2026-35216) in Budibase that can be triggered via webhooks and Bash automation, but no PoC, exploit, or patch is provided.
Vulert@vulert_officialPatch
The tweet alerts users to a critical misconfiguration in Budibase that permits unauthenticated RCE and urges immediate updates of self-hosted deployments.
Autumn Good@autumn_good_35Disclosure
The advisory announces an unauthenticated remote code execution vulnerability in Budibase’s webhook trigger and bash automation, providing a link to the official GitHub advisory but detailing no exploitation code, active attacks, or patch information.
The Hacker Wire@TheHackerWireDisclosure
The post announces CVE-2026-35216, which allows unauthenticated remote code execution on Budibase servers before v3.33.4, providing vulnerability specifics but no PoC, exploit code, patch, or evidence of active exploitation.
CVEFind.com@CveFindComPatch
Budibase released patch 3.33.4 to fix an unauthenticated remote code execution flaw triggered through a public webhook, confirming the vulnerability is remediated.
CVE@CVEnewDisclosure
The post announces CVE-2026-35216, exposing a Remote Code Execution flaw in Budibase versions earlier than 3.33.4, without mentioning an exploit, patch, or active use.
0day Signal@0dayPublishingDisclosure
The post announces CVE‑2026‑35216 against Budibase, describing an authentication‑free root RCE via a webhook‑to‑bash chain, with no PoC, exploit code, or patch mentioned.