CVE-2026-35216
CRITICALBudibase: Unauthenticated Remote Code Execution via Webhook Trigger and Bash Automation Step
Title source: cnaDescription
Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) on the Budibase server by triggering an automation that contains a Bash step via the public webhook endpoint. No authentication is required to trigger the exploit. The process executes as root inside the container. This issue has been patched in version 3.33.4.
Scores
CVSS v3
9.0
EPSS
0.0055
EPSS Percentile
68.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-78
Status
published
Products (3)
budibase/budibase
< 3.33.4
Budibase/budibase
< 3.33.4
budibase/server
0 - 3.33.4npm
Published
Apr 03, 2026
Tracked Since
Apr 03, 2026