CVE-2026-50136Disclosure(budibase / budibase)

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch budibase budibase systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Budibase is an open-source low-code platform. Prior to 3.39.3, the application server exposes an unauthenticated endpoint that generates S3 PutObject presigned URLs using credentials stored in a workspace datasource. The route is protected only by the recaptcha middleware and does not require authentication, table permission, datasource permission, or builder access. A public caller who knows a workspace ID and S3 datasource ID can request a signed upload URL for attacker-controlled bucket and key values. This vulnerability is fixed in 3.39.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • budibase

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-26); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
budibase

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-06-26: 2Mentions · 2026-06-27: 2Patch / Workaround · 2026-06-27: 1Technical Details · 2026-06-26: 2Technical Details · 2026-06-27: 206-2606-27
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Full discourse4 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    #CVE-2026-50136 - Supply Chain Attack in #Budibase. Unauthenticated endpoint exposes #S3 presigned URLs. #CVSS 7.4. No known patch. Mitigate immediately. #cybersecurity #devsecops #devops #git #github #gitlab #infosec More detailed info: https://www.valtersit.com/cve/CVE-2026-50136/

    Post summary

    The post announces CVE-2026-50136, a supply‑chain vulnerability in Budibase exposing unauthenticated S3 presigned URLs, notes a CVSS score of 7.4, and advises immediate mitigation while no patch is available.

    0003077
    1.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-50136 Unauthenticated S3 Presigned URL Generation in Budibase Prior to 3.39.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-50136

    Post summary

    The brief report announces an unauthenticated S3 presigned URL generation flaw in Budibase versions before 3.39.3, providing basic vulnerability details but no proof‑of‑concept, exploit code, or patch information.

    00010121
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-50136 Budibase is an open-source low-code platform. Prior to 3.39.3, the application server exposes an unauthenticated endpoint that generates S3 PutObject presigned URLs u… https://www.cve.org/CVERecord?id=CVE-2026-50136 ----- Traducción: CVE-2026-50136 Bud… http://infoflow.cloud`

    Post summary

    Budibase versions prior to 3.39.3 have an unauthenticated endpoint that can generate S3 PutObject presigned URLs, potentially enabling unauthorized access, but no PoC, exploit code, active exploitation, or patch information is provided.

    0001042
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-50136 Budibase is an open-source low-code platform. Prior to 3.39.3, the application server exposes an unauthenticated endpoint that generates S3 PutObject presigned URLs u… https://www.cve.org/CVERecord?id=CVE-2026-50136

    Post summary

    The post discloses that Budibase versions before 3.39.3 expose an unauthenticated endpoint for generating S3 presigned URLs, with no PoC, exploit, or patch details provided.

    00010694
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbudibasebudibase---

Explore more