What is CVE-2026-72859?
Budibase versions 3.39.4 before 3.40.0 contain an authorization regression in the S3 attachment upload endpoint. This allows BASIC users to obtain S3 PutObject presigned URLs by sending POST requests to the attachments endpoint. Users should immediately update to version 3.40.0 or later.
Azərbaycanca: Budibase platformasının 3.39.4-dən əvvəlki 3.40.0 versiyalarında S3 fayl yükləmə funksiyasında avtorizasiya zəifliyi aşkarlanıb. Bu, BASIC səviyyəli istifadəçilərə əlavə POST sorğuları göndərərək S3 PutObject presigned URL-ləri əldə etməyə imkan verir. İstifadəçilər dərhal 3.40.0 və ya daha yeni versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: Budibase
FAQ2
Which versions of the Budibase platform are affected by CVE-2026-72859?
This vulnerability affects Budibase versions 3.39.4 before 3.40.0.
What can a BASIC user obtain by exploiting CVE-2026-72859?
A BASIC user can obtain S3 PutObject presigned URLs by sending POST requests to the attachments endpoint.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.