PT-2026-72008 · Budibase · Budibase
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
Budibase version 3.39.4
Description
An authorization regression exists in the S3 attachment upload endpoint. This issue allows users with BASIC permissions to obtain S3 PutObject presigned URLs by sending POST requests to the attachments endpoint. The vulnerability occurred because the route permission check was changed from BUILDER to TABLE/WRITE, a permission that BASIC users possess by default. An attacker can specify arbitrary S3 buckets in the request body to generate presigned URLs, enabling unauthorized file uploads to any bucket accessible by the stored IAM credentials.
Recommendations
Update Budibase to version 3.40.0.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Budibase