Critical RCE Vulnerability in Budibase Affects Versions Before 3.41.3

Critical RCE Vulnerability in Budibase Affects Versions Before 3.41.3

First seen 29 Aug 2026, 15:48 UTC Feedlyexploit-intel.comvuldb.com 70.5

Article Content

Browse articles
ThreatCluster

Budibase versions prior to 3.41.3 have a critical remote code execution (RCE) vulnerability identified as CVE-2026-82244. This flaw allows authenticated admin users to upload malicious plugin tarballs, leading to arbitrary code execution due to the server's use of eval() on untrusted JavaScript files without sandboxing. Attackers can exploit this vulnerability to exfiltrate sensitive information, including environment variables and credentials, with root privileges. Currently, no evidence of exploitation in the wild or public proof-of-concept exists. A patch is available, and it is recommended to upgrade to version 3.41.3 or later. Additionally, restricting admin access to trusted users and monitoring for suspicious plugin uploads is advised. The CVSS score for this vulnerability is reported as 9.4, indicating a critical severity level.

Key Points: • Budibase versions before 3.41.3 are vulnerable to RCE via malicious plugin uploads. • The vulnerability allows attackers to execute arbitrary code with root privileges. • A patch is available; upgrading is strongly recommended to mitigate risks.

Timeline

2026-08-28
CVE-2026-82244 published
CVE-2026-82244 was officially published, detailing a critical RCE vulnerability in Budibase.
exploit-intel.com
2026-08-29
Exploit details disclosed
Details about the RCE vulnerability were disclosed, emphasizing the risk of arbitrary code execution through plugin handling.
Feedly
2026-08-29
Patch recommendation issued
Users are advised to upgrade to Budibase version 3.41.3 or later to mitigate the vulnerability.
Feedly