Junglewise Threat Intelligence

CVE-2026-50136: Budibase missing authentication in S3 signed URL generation

CVE-2026-50136 · Severity: high · CVSS 7.4 · Published 2026-06-26

Technologies: @budibase/server (npm), Budibase. Vendors: npm, Budibase.

Executive brief

Budibase is an open-source platform used by businesses to build internal applications and workflows. A security flaw in the application server allows unauthorized individuals to generate special upload links that use the company's stored Amazon S3 credentials. This could allow an attacker to upload malicious files, overwrite existing data, or incur storage costs using the organization's cloud account.

Technical details

The Budibase application server contains a missing authentication vulnerability (CWE-306) in the `/api/attachments/:datasourceId/url` endpoint. The route is protected only by reCAPTCHA middleware and fails to verify authentication, table permissions, or builder access. An attacker who knows a workspace ID and an S3 datasource ID can provide an arbitrary bucket and key name to receive a signed upload URL. This URL is generated using the secret access keys stored in the workspace's datasource configuration, enabling the attacker to perform arbitrary writes to any S3 bucket accessible by those credentials. The issue is resolved in version 3.39.3.

Affected products

  • Budibase Budibase < 3.39.3

Timeline

  • 2026-05-28: advisory: GitHub Security Advisory published
  • 2026-06-26: disclosed: CVE published to NVD

References

Related threats