CRITICALVulnerability

CVE-2026-72850

Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are preserved during export. Attackers can craft filenames containing .. segments that escape the temporary directory during workspace export, writing arbitrary content to any path writable by the Budibase process.

Properties

severity
CRITICAL
score
9.1
epss_score
0.00422
cve_id
CVE-2026-72850
vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
published_at
2026-08-13T22:17:24.307
last_modified
2026-08-31T20:33:07.713
epss_percentile
0.35327

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-72850 — Ninja Signal Threat Intelligence | Ninja Signal