CVE-2026-35216 is a critical unauthenticated Remote Code Execution (RCE) vulnerability affecting Budibase, an open-source low-code platform, in versions prior to 3.33.4. An attacker can exploit this by triggering a public webhook that executes a Bash automation step, gaining root-level control within the server's container without authentication. Rated 9.0 CRITICAL on CVSS, this vulnerability has a network attack vector and high impact on confidentiality, integrity, and availability, despite a high attack complexity. While currently not listed on CISA's KEV catalog and lacking public exploit code, it is on the "Hot List: Active" indicating elevated risk and has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.33.4CPE matchmatch criteria | cpe:2.3:a:budibase:budibase:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.4 Reddit, 1.2 Bluesky, 0.8 Mastodon, and 2.3 GitHub mentions.
The average CVE in this peer group has 0.8 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.