exploit-intel.com
Critical RCE Vulnerability in Budibase Affects Versions Before 3.41.3
Article Content
Budibase versions prior to 3.41.3 have a critical remote code execution (RCE) vulnerability identified as CVE-2026-82244. This flaw allows authenticated admin users to upload malicious plugin tarballs, leading to arbitrary code execution due to the server's use of eval() on untrusted JavaScript files without sandboxing. Attackers can exploit this vulnerability to exfiltrate sensitive information, including environment variables and credentials, with root privileges. Currently, no evidence of exploitation in the wild or public proof-of-concept exists. A patch is available, and it is recommended to upgrade to version 3.41.3 or later. Additionally, restricting admin access to trusted users and monitoring for suspicious plugin uploads is advised. The CVSS score for this vulnerability is reported as 9.4, indicating a critical severity level.
Key Points: • Budibase versions before 3.41.3 are vulnerable to RCE via malicious plugin uploads. • The vulnerability allows attackers to execute arbitrary code with root privileges. • A patch is available; upgrading is strongly recommended to mitigate risks.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.