PT-2026-30192 · Budibase · Budibase

Published

2026-04-03

·

Updated

2026-04-03

·

CVE-2026-35216

CVSS v3.1

9.0

Critical

AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) on the Budibase server by triggering an automation that contains a Bash step via the public webhook endpoint. No authentication is required to trigger the exploit. The process executes as root inside the container. This issue has been patched in version 3.33.4.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-35216

Affected Products

Budibase