Arbitrary File Write in Budibase Server via PWA Icon Upload
Budibase Server versions prior to 3.45.0 allow authenticated BUILDER role users to achieve arbitrary file write and remote code execution by uploading malicious ZIP archives to the PWA icon upload endpoint.
CVE search metadata
CVE search record: CVE-2026-100682. Severity: high. CVSS: 8.8. KEV: no. Product: Budibase Server (< 3.45.0). Brief: Arbitrary File Write in Budibase Server via PWA Icon Upload. Brief link: https://feed.craftedsignal.io/briefs/2026-09-budibase-arbitrary-file-write/
Budibase Server versions before 3.45.0 are susceptible to an arbitrary file write vulnerability within the PWA (Progressive Web App) icon upload functionality. The application fails to properly validate symlink entries when extracting user-supplied ZIP archives. By crafting a ZIP file containing specific symlink structures combined with duplicate file entries, an authenticated attacker possessing the BUILDER role can traverse the filesystem to overwrite sensitive files. This vulnerability facilitates arbitrary code execution as the root user, significantly impacting the confidentiality, integrity, and availability of the host environment. Defenders should prioritize patching to version 3.45.0 or later and audit access logs for suspicious administrative activity within the Budibase management interface.
Impact
Successful exploitation allows an attacker to gain remote code execution with root-level privileges on the server hosting the Budibase instance. This provides complete control over the application environment and the underlying host. The vulnerability specifically targets the Budibase Server software in enterprise environments where the BUILDER role is assigned to users.
Recommendation
- Patch Budibase Server to version 3.45.0 or later immediately to address CVE-2026-100682.
- Review administrative access controls and audit users assigned the BUILDER role to minimize the attack surface.
- Monitor webserver access logs for anomalous POST requests directed at PWA icon upload endpoints.
Immediate actions
Upgrade Budibase Server to version 3.45.0
Mitigations
Upgrade Budibase Server to 3.45.0
CVE-2026-100682