Sploitus

CVE-2026-72850

No indexed exploits for CVE-2026-72850 yet

Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are preserved during export. Attackers can craft filenames containing .. segments that escape the temporary directory during workspace export, writing arbitrary content to any path writable by the Budibase process.

Affected products
Budibase
Fix
Available
CVSS 4.0
9.4 CRITICAL
CVSS 3.1
9.1 CRITICAL
EPSS
0.4% (35th percentile)
Weakness
CWE-22
NVD status
Received
Published
2026-08-13
CVE-2026-72850 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-72850 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-72850 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.