Unauthenticated Endpoint in Budibase Allows Unrestricted S3 Uploads
CVE-2026-50136

7.4HIGH

Key Information:

Vendor

Budibase

Status
Vendor
CVE Published:
26 June 2026

What is CVE-2026-50136?

Budibase, an open-source low-code platform, has an unauthenticated endpoint that allows the generation of S3 PutObject presigned URLs using credentials stored in a workspace datasource. This security issue arises from the endpoint being protected solely by recaptcha middleware, lacking essential authentication methods such as table permissions, datasource permissions, or builder access. An attacker can exploit this by knowing the workspace ID and S3 datasource ID, enabling them to request a signed upload URL that can direct uploads to any bucket and key values they specify. This vulnerability has been addressed in version 3.39.3.

Affected Version(s)

budibase < 3.39.3

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.