{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/budibase-3.39.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Budibase (3.39.4)"],"_cs_severities":["high"],"_cs_tags":["authorization-bypass","privilege-escalation","cloud-security","s3","web-application"],"_cs_type":"advisory","_cs_vendors":["Budibase"],"content_html":"\u003cp\u003eA significant authorization regression in Budibase version 3.39.4 allows any authenticated BASIC app user to generate S3 PutObject presigned URLs. This vulnerability stems from an incorrect permission level assigned to the S3 attachment upload endpoint, which was downgraded from the intended \u003ccode\u003eBUILDER\u003c/code\u003e level to \u003ccode\u003eTABLE/WRITE\u003c/code\u003e. As BASIC users possess \u003ccode\u003eTABLE/WRITE\u003c/code\u003e permissions by default, they can exploit this flaw to obtain valid S3 presigned URLs. Critically, the controller responsible for handling these requests fails to validate the target S3 bucket, meaning an attacker can specify any S3 bucket the underlying IAM credentials have access to, rather than being restricted to the application's configured bucket. This exposes organizations using vulnerable Budibase instances to unauthorized data modification or exfiltration in connected S3 storage. The issue was published in July 2026 and represents a privilege escalation threat impacting cloud environments.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker, with existing BASIC user credentials for a Budibase application, authenticates to the application.\u003c/li\u003e\n\u003cli\u003eThe attacker discovers or obtains a valid S3 datasource ID configured within the Budibase application.\u003c/li\u003e\n\u003cli\u003eThe attacker sends a specially crafted HTTP POST request to the \u003ccode\u003e/api/attachments/\u0026lt;datasourceId\u0026gt;/url\u003c/code\u003e endpoint, specifying a target S3 bucket (e.g., \u003ccode\u003etarget-bucket\u003c/code\u003e) and a malicious key (e.g., \u003ccode\u003emalicious-file.html\u003c/code\u003e) in the request body.\u003c/li\u003e\n\u003cli\u003eDue to the authorization regression, the Budibase server validates the BASIC user's \u003ccode\u003eTABLE/WRITE\u003c/code\u003e permissions and processes the request.\u003c/li\u003e\n\u003cli\u003eThe server responds with a valid S3 PutObject presigned URL that grants temporary write access to the attacker-specified bucket and key.\u003c/li\u003e\n\u003cli\u003eThe attacker utilizes the obtained presigned URL to upload arbitrary content (e.g., malware, exfiltrated data) to the designated S3 bucket.\u003c/li\u003e\n\u003cli\u003eThe malicious content is successfully uploaded to the S3 bucket, leveraging the compromised IAM credentials of the Budibase instance.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of this vulnerability grants low-privileged BASIC users the ability to perform unauthorized write operations to any S3 bucket accessible by the Budibase application's stored IAM credentials. This can lead to a variety of severe impacts, including data corruption by overwriting legitimate files, data exfiltration by uploading sensitive data to attacker-controlled buckets, or the introduction of malicious content (e.g., web shells, backdoors) if the target bucket serves static web content. The exact number of affected organizations is not specified, but any organization utilizing Budibase v3.39.4 or later unpatched versions with S3 integrations is at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update Budibase installations to a patched version that addresses the CVE and restores the intended authorization logic.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to your webserver logs to detect suspicious POST requests to the S3 attachment upload endpoint.\u003c/li\u003e\n\u003cli\u003eMonitor cloud audit logs (e.g., AWS CloudTrail) for unusual \u003ccode\u003es3:PutObject\u003c/code\u003e API calls, especially those initiated by IAM roles associated with Budibase that write to buckets outside of their normal operational scope.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-24T21:20:41Z","date_published":"2026-07-24T21:20:41Z","id":"https://feed.craftedsignal.io/briefs/2026-07-budibase-s3-presigned-url-auth-regression/","summary":"A regression in Budibase v3.39.4 allows BASIC app users to bypass authorization controls and obtain S3 PutObject presigned URLs, enabling low-privileged users to upload arbitrary content to any S3 bucket that the system's stored IAM credentials can access.","title":"Budibase S3 Presigned URL Authorization Regression","url":"https://feed.craftedsignal.io/briefs/2026-07-budibase-s3-presigned-url-auth-regression/"}],"language":"en","title":"CraftedSignal Threat Feed - Budibase (3.39.4)","version":"https://jsonfeed.org/version/1.1"}