Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35216

40
FAUCET Score

CVE-2026-35216 is a critical unauthenticated Remote Code Execution (RCE) vulnerability affecting Budibase, an open-source low-code platform, in versions prior to 3.33.4. An attacker can exploit this by triggering a public webhook that executes a Bash automation step, gaining root-level control within the server's container without authentication. Rated 9.0 CRITICAL on CVSS, this vulnerability has a network attack vector and high impact on confidentiality, integrity, and availability, despite a high attack complexity. While currently not listed on CISA's KEV catalog and lacking public exploit code, it is on the "Hot List: Active" indicating elevated risk and has garnered some community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.33.4CPE matchmatch criteria
cpe:2.3:a:budibase:budibase:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.0CRITICAL

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
11.98%
Probability of exploitation in next 30 days
EPSS Percentile
95.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.1198 is in the 90th percentile among its peer group of 200 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.4 Reddit, 1.2 Bluesky, 0.8 Mastodon, and 2.3 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.8 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: @budibase/serverFixed in: 3.33.4

Vendor Advisories (1)

npmGHSA-fcm4-4pj2-m5hfcritical

Budibase: Unauthenticated Remote Code Execution via Webhook Trigger and Bash Automation Step

Apr 4, 2026

References

github.com / Budibase/budibase/commit/f0c731b409a96e401445a6a6030d2994ff4ac256
Patch
github.com / Budibase/budibase/pull/18238
Issue TrackingPatch
github.com / Budibase/budibase/releases/tag/3.33.4
ProductRelease Notes
github.com / Budibase/budibase/security/advisories/GHSA-fcm4-4pj2-m5hf
ExploitVendor Advisory