<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Budibase Server (&lt; 3.45.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/budibase-server--3.45.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 26 Sep 2026 15:11:52 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/budibase-server--3.45.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Arbitrary File Write in Budibase Server via PWA Icon Upload</title><link>https://feed.craftedsignal.io/briefs/2026-09-budibase-arbitrary-file-write/</link><pubDate>Sat, 26 Sep 2026 15:11:52 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-budibase-arbitrary-file-write/</guid><description>Budibase Server versions prior to 3.45.0 allow authenticated BUILDER role users to achieve arbitrary file write and remote code execution by uploading malicious ZIP archives to the PWA icon upload endpoint.</description><content:encoded><![CDATA[<p>Budibase Server versions before 3.45.0 are susceptible to an arbitrary file write vulnerability within the PWA (Progressive Web App) icon upload functionality. The application fails to properly validate symlink entries when extracting user-supplied ZIP archives. By crafting a ZIP file containing specific symlink structures combined with duplicate file entries, an authenticated attacker possessing the BUILDER role can traverse the filesystem to overwrite sensitive files. This vulnerability facilitates arbitrary code execution as the root user, significantly impacting the confidentiality, integrity, and availability of the host environment. Defenders should prioritize patching to version 3.45.0 or later and audit access logs for suspicious administrative activity within the Budibase management interface.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an attacker to gain remote code execution with root-level privileges on the server hosting the Budibase instance. This provides complete control over the application environment and the underlying host. The vulnerability specifically targets the Budibase Server software in enterprise environments where the BUILDER role is assigned to users.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Patch Budibase Server to version 3.45.0 or later immediately to address CVE-2026-100682.</li>
<li>Review administrative access controls and audit users assigned the BUILDER role to minimize the attack surface.</li>
<li>Monitor webserver access logs for anomalous POST requests directed at PWA icon upload endpoints.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>arbitrary-file-write</category><category>rce</category><category>web-vulnerability</category></item></channel></rss>