What is CVE-2026-54356?
In Budibase platform, an authenticated user can specify an attacker-controlled bucket via the file upload API. This vulnerability affects versions prior to 3.41.3. An immediate upgrade to version 3.41.3 or newer is required.
Azərbaycanca: Budibase platformunda autentifikasiya olunmuş istifadəçi fayl yükləmə API-si vasitəsilə attacker tərəfindən idarə olunan bucket-i təyin edə bilir. Bu zəiflik 3.41.3 versiyasından əvvəlki versiyaları təsir edir. Dərhal 3.41.3 və ya daha yeni versiyaya yenilənməlidir.
Related CVEs
link basis: shared vendor: Budibase
FAQ2
Does exploiting CVE-2026-54356 require the attacker to be authenticated?
Yes, exploiting this vulnerability requires the attacker to be an authenticated user on the Budibase platform.
Which Budibase versions are affected by CVE-2026-54356?
This vulnerability affects all Budibase versions prior to 3.41.3.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.