CVE-2026-72850
Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are preserved during export. Attackers can craft filenames containing .. segments that escape the temporary directory during workspace export, writing arbitrary content to any path writable by the Budibase process.
- Affected products
- Budibase
- Fix
- Available
- CVSS 4.0
- 9.4 CRITICAL
- CVSS 3.1
- 9.1 CRITICAL
- EPSS
- 0.4% (35th percentile)
- Weakness
- CWE-22
- NVD status
- Received
- Published
- 2026-08-13
CVE-2026-72850 at NVD
No indexed exploits for CVE-2026-72850 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-72850 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.