What is CVE-2026-72850?
CVE-2026-72850 is a vulnerability in Budibase before 3.40.0 where improper sanitization of S3 object keys allows authenticated builders to craft filenames with path traversal sequences, escaping the temporary directory during workspace export to write arbitrary files.
Azərbaycanca: CVE-2026-72850 Budibase platformunda autentifikasiya olunmuş builder istifadəçilərinə S3 obyekt açarlarını düzgün sanitizə etmədən, fayl adlarına path traversal ardıcıllığı əlavə edərək ixrac zamanı müvəqqəti qovluqdan kənara yazmağa imkan verən boşluqdur. 3.40.0 versiyasından əvvəlki versiyalar təsirlənir və dərhal yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
What level of access is required to exploit CVE-2026-72850?
Exploiting this vulnerability requires being an authenticated builder user on the Budibase platform.
Which versions of Budibase are affected by CVE-2026-72850?
This vulnerability affects all versions of Budibase prior to version 3.40.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.