CVE-2026-35216
CRITICALBudibase: Unauthenticated Remote Code Execution via Webhook Trigger and Bash Automation Step
Title source: cnaDescription
Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) on the Budibase server by triggering an automation that contains a Bash step via the public webhook endpoint. No authentication is required to trigger the exploit. The process executes as root inside the container. This issue has been patched in version 3.33.4.
References (4)
Core 4
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/Budibase/budibase/security/advisories/GHSA-fcm4-4pj2-m5hf
X_Refsource_Misc x_refsource_misc
https://github.com/Budibase/budibase/pull/18238
X_Refsource_Misc x_refsource_misc
https://github.com/Budibase/budibase/commit/f0c731b409a96e401445a6a6030d2994ff4ac256
X_Refsource_Misc x_refsource_misc
https://github.com/Budibase/budibase/releases/tag/3.33.4
Scores
CVSS v3
9.0
EPSS
0.1198
EPSS Percentile
95.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-78
Status
published
Products (3)
budibase/budibase
< 3.33.4
Budibase/budibase
< 3.33.4
budibase/server
0 - 3.33.4npm
Published
Apr 03, 2026
Tracked Since
Apr 03, 2026