CRITICAL
9.1 CVE-2026-82244 Published 28 Aug 2026
Budibase RCE via Malicious Plugin Upload
Worried this affects one of your servers?
Budibase versions before 3.41.3 contain a serious vulnerability.
Authenticated admin users can exploit this by uploading a malicious plugin tarball.
The server runs uploaded JavaScript files with eval() in the main Node.js process, bypassing sandboxing.
Attackers can execute arbitrary code, exfiltrate environment variables, and steal credentials with root privileges in default deployments.
Reference: CVE-2026-82244 on NVD
← Back to Security News