{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-72850/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-72850"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["server"],"_cs_severities":["critical"],"_cs_tags":["webserver","path-traversal","cve-2026-72850","web-vulnerability","sqli","remote-code-execution"],"_cs_type":"advisory","_cs_vendors":["Budibase"],"content_html":"\u003cp\u003eBudibase versions prior to 3.40.0 contain a critical path traversal vulnerability (CVE-2026-72850) affecting the handling of S3 object keys. The flaw originates in the application's failure to sanitize filenames provided during file uploads within the builder interface. When an authenticated user with builder privileges uploads a file containing directory traversal sequences (e.g., ../), these sequences are incorrectly preserved.\u003c/p\u003e\n\u003cp\u003eThe vulnerability is triggered during the workspace export process. When the application processes these files, the lack of path validation allows the file contents to be written to arbitrary locations on the host filesystem that are writable by the Budibase service account. This allows an attacker to potentially overwrite configuration files, inject scripts, or place malicious binaries, leading to remote code execution or system compromise. Defenders should prioritize upgrading to version 3.40.0 or later to remediate the vulnerability.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to the Budibase builder interface with valid builder-level credentials.\u003c/li\u003e\n\u003cli\u003eAttacker initiates a file upload process for an S3-backed resource.\u003c/li\u003e\n\u003cli\u003eAttacker intercepts the upload request or modifies the request to include a filename containing directory traversal sequences (e.g., ../../etc/cron.d/malicious_job).\u003c/li\u003e\n\u003cli\u003eThe Budibase application accepts and stores the malicious S3 object key without sanitization.\u003c/li\u003e\n\u003cli\u003eAttacker triggers a workspace export action within the application.\u003c/li\u003e\n\u003cli\u003eThe backend export logic processes the stored malicious object keys.\u003c/li\u003e\n\u003cli\u003eThe application writes the file content to the target directory on the filesystem outside of the intended temporary directory.\u003c/li\u003e\n\u003cli\u003eAttacker executes the injected content (e.g., via cron or web shell placement) to achieve remote code execution.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows for arbitrary file writes, which in a server environment typically leads to full remote code execution and complete system compromise. This poses a significant risk to the integrity and availability of the Budibase deployment. Given that this requires authenticated access, the impact is primarily targeted at organizations where builder accounts may be compromised or provisioned to untrusted users.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Budibase server to version 3.40.0 or later immediately to patch CVE-2026-72850.\u003c/li\u003e\n\u003cli\u003eAudit access logs for the Budibase application to identify any user accounts that have performed unusual export actions or bulk file uploads.\u003c/li\u003e\n\u003cli\u003eMonitor filesystem activity on the Budibase server for unexpected file writes, particularly in directories outside of the application's designated data and temporary folders, using host-based instrumentation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-14T00:06:30Z","date_published":"2026-08-14T00:06:06Z","id":"https://feed.craftedsignal.io/briefs/2026-08-budibase-traversal/","summary":"Budibase versions before 3.40.0 are vulnerable to path traversal via maliciously crafted S3 object keys, allowing authenticated builders to perform arbitrary file writes during workspace export.","title":"Path Traversal Vulnerability in Budibase","url":"https://feed.craftedsignal.io/briefs/2026-08-budibase-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-72850","version":"https://jsonfeed.org/version/1.1"}