9.1
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Description
Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) on the Budibase server by triggering an automation that contains a Bash step via the public webhook endpoint. No authentication is required to trigger the exploit. The process executes as root inside the container. This issue has been patched in version 3.33.4.
Basic Information
ID
CVE-2026-35216
Source
GitHub_M
Published
Apr 3, 2026 at 15:45
Modified
Apr 3, 2026 at 16:46
Affected Product
Vendor
Budibase
Product
budibase
Version
< 3.33.4
Affected Versions
Budibase budibase < 3.33.4