PT-2026-99353 · Budibase · @Budibase/Server

·

CVE-2026-100682

·

Published

2026-09-26

·

Updated

2026-09-29

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Budibase Server versions prior to 3.45.0
Description An arbitrary file write issue exists in the PWA icon upload endpoint. The system extracts user-supplied ZIP archives without proper symlink validation. Users with the BUILDER role can create a malicious ZIP file containing leaf symlink entries followed by duplicate file entries to write arbitrary files as root, which can lead to remote code execution.
Recommendations Update Budibase Server to version 3.45.0 or later.

Exploit

Fix

RCE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100682
GHSA-37R6-5JXH-VM83

Affected Products

@Budibase/Server