Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-50137— Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentials

Quick assessment

Affected
Budibase budibase
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Budibase是英国Budibase公司开源的一个用于在几分钟内创建内部应用程序、工作流和管理面板的低代码平台。 Budibase 3.39.0之前版本存在授权问题漏洞,该漏洞源于授权缺失,可能导致匿名攻击者通过已知工作区ID和数据源ID获取预签名PUT URL,并向任意S3存储桶写入数据。

AI Predicted 8.6 Difficulty: Easy EPSS 0.41% · P33

Possible ATT&CK Techniques 1 AI

T1528 · Steal Application Access Token

Affected Version Matrix 1

VendorProduct Version RangeStatus
Budibase budibase < 3.39.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-50137

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentials
Source: CVE Program / CVE List V5
Vulnerability Description
Budibase is an open-source low-code platform. Prior to 3.39.0, an anonymous attacker who knows or can enumerate a workspace id (app_...) and an S3-source datasource id (ds_...) can call this endpoint with no auth and obtain a 15-minute pre-signed PUT URL minted on the victim's IAM identity. The endpoint also returns the publicUrl so the attacker knows exactly where their PUT lands. Because bucket is attacker-controlled, the attacker can write to any bucket those IAM credentials can write to, not only the bucket the datasource was configured for. The Budibase server route POST /api/attachments/:datasourceId/url (packages/server/src/api/routes/static.ts) is registered with only the recaptcha middleware. There is no authorized(...) middleware in the chain. The controller (packages/server/src/api/controllers/static/index.ts::getSignedUploadURL) looks the requested datasource up, instantiates an AWS S3 client with the datasource's stored accessKeyId / secretAccessKey, and returns an AWS Signature V4 pre-signed PutObjectCommand URL for the caller-supplied bucket and key. The bucket is not pinned to the datasource's configured bucket. The workspace context required by sdk.datasources.get is sourced by getWorkspaceIdFromCtx (packages/backend-core/src/utils/utils.ts) from any of: the x-budibase-app-id header, the JSON body appId, a path segment that begins with the workspace prefix, or ?appId=. auth.buildAuthMiddleware([], { publicAllowed: true }) runs before any of this and explicitly allows anonymous requests. The currentWorkspace middleware's "deny access to dev preview" branch only triggers under isBrowser(ctx) && !isApiKey(ctx); isBrowser checks the parsed User-Agent for a recognised browser, so any non-browser client (curl, the supplied PoC, any tool not setting a browser UA) is neither and reaches dev workspaces too. This vulnerability is fixed in 3.39.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5
Vulnerability Title
Budibase 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Budibase是英国Budibase公司开源的一个用于在几分钟内创建内部应用程序、工作流和管理面板的低代码平台。 Budibase 3.39.0之前版本存在授权问题漏洞,该漏洞源于授权缺失,可能导致匿名攻击者通过已知工作区ID和数据源ID获取预签名PUT URL,并向任意S3存储桶写入数据。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Budibase budibase < 3.39.0 -

II. Public POCs for CVE-2026-50137

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-50137

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-50137 (1)

Same Patch Batch · Budibase · 2026-06-26 · 7 CVEs total

CVE-2026-54350 10.0 CRITICAL Budibase: Anonymous NoSQL operator injection via published-app query templates
CVE-2026-54352 9.6 CRITICAL Budibase: Arbitrary file read by workspace-builder via PWA-zip symlink upload
CVE-2026-54353 8.5 HIGH Budibase: Potential SSRF DNS rebinding bypass in outbound fetch validation
CVE-2026-54351 8.2 HIGH Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution v
CVE-2026-50136 7.4 HIGH Budibase: Unauthenticated S3 signed upload URL generation allows arbitrary writes with sto
CVE-2026-50132 7.3 HIGH Budibase: Chat Identity Link Hijacking via Missing Consent & CSRF — Account Impersonation

IV. Related Vulnerabilities

V. Comments for CVE-2026-50137

No comments yet


Leave a comment