Budibase Patches Critical RCE and SSRF Vulnerabilities
ID: 83cadd47-a37b-5dc5-b135-e8a8f8f8f1c5
STIX ID: report--83cadd47-a37b-5dc5-b135-e8a8f8f8f1c5
Feed Name: securityonline.info
Budibase released urgent patches for two critical vulnerabilities affecting self-hosted deployments (<= 3.30.6): an unauthenticated RCE (CVE-2026-35216) via Bash automation webhooks and an SSRF (CVE-2026-31818) caused by an unset BLACKLIST_IPS allowing requests to internal services; successful exploitation can lead to root command execution in the container, exfiltration of JWTs, database/API credentials, and full access to the CouchDB data layer. Administrators are advised to upgrade to version 3.33.4, audit automations that use Bash steps, and set BLACKLIST_IPS if they cannot immediately update.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
