Junglewise Threat Intelligence

CVE-2026-72859: Budibase S3 presigned URL authorization regression

CVE-2026-72859 · Severity: low · CVSS 3.1 · Published 2026-07-24

Technologies: @budibase/server (npm), Budibase. Vendors: npm, Budibase.

Executive brief

Budibase is a low-code platform for building business applications and automations. A regression in version 3.39.4 allows basic app users to generate S3 file upload URLs (presigned URLs) that should only be available to admin/builder users. An attacker with basic user access can exploit this to write arbitrary files to any S3 bucket connected to the application, potentially compromising data integrity and enabling malicious content injection.

Technical details

The vulnerability is an authorization bypass (CWE-863) in the S3 attachment upload endpoint (/api/attachments/:datasourceId/url). The route's permission check was incorrectly changed from BUILDER level (v3.39.3) to TABLE/WRITE level (v3.39.4) in a regression. Since BASIC app users have default TABLE/WRITE permissions, they can now call this endpoint. Additionally, the controller accepts the S3 bucket name directly from the request body without validating it against the datasource's configured bucket, allowing writes to any S3 bucket accessible by the application's IAM credentials. The attack requires network access and a valid Budibase app user account with BASIC role or higher. The vulnerability is fixed in version 3.40.0 by restoring the BUILDER authorization requirement and pinning bucket writes to the configured datasource bucket.

Affected products

  • Budibase Budibase <3.40.0 (affected from v3.39.4; fixed in v3.40.0)

Timeline

  • 2026-07-24: disclosed
  • 2026-07-22: patched: Fix released in version 3.40.0

References

Related threats