PatchSiren cyber security CVE debrief
CVE-2026-54356 Budibase CVE debrief
Budibase open-source low-code platform vulnerability allows authenticated users to obtain signed and public URLs backed by stored S3 credentials. Fixed in version 3.41.3. The issue arises from inadequate validation of user-supplied input, enabling attackers to manipulate bucket and key values. This could lead to unauthorized access to sensitive data stored in S3. Users with the BASIC role in published apps are affected. The vulnerability is addressed in version 3.41.3, which includes patches to prevent such manipulation.
- Vendor
- Budibase
- Product
- Unknown
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-17
- Original CVE updated
- 2026-09-08
- Advisory published
- 2026-08-17
- Advisory updated
- 2026-09-08
Who should care
Budibase administrators and users with the BASIC role in published apps should assess exposure and upgrade to version 3.41.3 or later to prevent unauthorized access to S3 credentials.
Why it matters
CVE-2026-54356 Budibase vulnerability allows authenticated users to obtain signed and public URLs backed by stored S3 credentials, requiring remediation to prevent unauthorized access.
- Potential unauthorized access to S3 credentials
- Possible misuse of signed and public URLs
- Required verification of Budibase instance vulnerability
- Necessity to restrict access to S3 datasources
Technical summary
Budibase open-source low-code platform vulnerability allows authenticated published-app users with the BASIC role to supply attacker-controlled bucket and key values and obtain signedUrl and publicUrl values backed by stored S3 datasource credentials. The issue is caused by insufficient input validation, allowing attackers to manipulate S3 credentials. This could lead to unauthorized access to sensitive data. The vulnerability is fixed in version 3.41.3, which enhances input validation and restricts unauthorized access.
Defensive priority
Remediate vulnerable Budibase instances to prevent unauthorized access to S3 credentials
Recommended defensive actions
- Upgrade Budibase to version 3.41.3 or later
- Review and restrict access to S3 datasources
- Monitor for suspicious activity on Budibase instances
- Verify the integrity of stored S3 credentials
- Implement additional logging and monitoring for S3 interactions
- Conduct a thorough review of Budibase instance configurations
- whoShouldCare
Evidence notes
CVE and NVD records indicate vulnerability in Budibase versions prior to 3.41.3. Vendor provides fix in version 3.41.3. The vulnerability allows authenticated published-app users with the BASIC role to supply attacker-controlled bucket and key values and obtain signedUrl and publicUrl values backed by stored S3 datasource credentials. Evidence is based on CVE and NVD records, which detail the vulnerability and its fix.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-54356 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-54356
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-54356 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-54356
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/Budibase/budibase/releases/tag/3.41.3
-
Source reference
Unverified legacy reference
URL: https://github.com/Budibase/budibase/security/advisories/GHSA-6x9p-4r67-5gjx
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.