PT-2026-72008 · Budibase · Budibase

·

CVE-2026-72859

·

Published

2026-07-24

·

Updated

2026-08-14

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Budibase version 3.39.4
Description An authorization regression exists in the S3 attachment upload endpoint. This issue allows users with BASIC permissions to obtain S3 PutObject presigned URLs by sending POST requests to the attachments endpoint. The vulnerability occurred because the route permission check was changed from BUILDER to TABLE/WRITE, a permission that BASIC users possess by default. An attacker can specify arbitrary S3 buckets in the request body to generate presigned URLs, enabling unauthorized file uploads to any bucket accessible by the stored IAM credentials.
Recommendations Update Budibase to version 3.40.0.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72859
GHSA-XCX6-4F2G-HHGX

Affected Products

Budibase