Hugo | DevOps | Cybersecurity 🇱🇻[verified]@HugoValtersPatch
The tweet discloses CVE-2026-54350, a critical CSRF flaw in Budibase, noting that no patch is available yet and recommends disabling public write queries as a mitigation.
ADK Cyber[verified]@ADKCyberPatch
The tweet alerts Budibase users to CVE‑2026‑54350, a critical flaw exposing database documents, and directs them to patch to version 3.39.12.
Upwind Security MDR[verified]@UpwindMDRDisclosure
The post announces CVE‑2026‑54350, a critical NoSQL operator injection in Budibase Server’s published‑app query templates that permits unauthenticated data exfiltration and write operations, noting that no patch is currently available.
DailyCVE@dailycveDisclosure
The post announces CVE-2026-54350, describing it as a JSON and NoSQL injection flaw in Budibase Server, but does not provide PoC, exploit, or mitigation details.
takenaka hiroya@Joe_Biden_jaDisclosure
A new CVE (2026-54350) for Budibase is disclosed, rated CVSS 10.0 with unauthenticated full read/write capabilities. No PoC, exploit code, or patch information is provided.
Infoflowcloud@infoflowcloudDisclosure
The tweet announces CVE‑2026‑54350, noting that in Budibase versions before 3.39.12 any unauthenticated visitor can read all MongoDB documents; no PoC, exploit, or patch details are shared.
CVE@CVEnewPatch
Budibase apps prior to version 3.39.12 allow unauthenticated users to read all MongoDB documents, and updating to 3.39.12 patches the flaw.