PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-54356 Budibase CVE debrief

Budibase open-source low-code platform vulnerability allows authenticated users to obtain signed and public URLs backed by stored S3 credentials. Fixed in version 3.41.3. The issue arises from inadequate validation of user-supplied input, enabling attackers to manipulate bucket and key values. This could lead to unauthorized access to sensitive data stored in S3. Users with the BASIC role in published apps are affected. The vulnerability is addressed in version 3.41.3, which includes patches to prevent such manipulation.

Vendor
Budibase
Product
Unknown
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-17
Original CVE updated
2026-09-08
Advisory published
2026-08-17
Advisory updated
2026-09-08

Who should care

Budibase administrators and users with the BASIC role in published apps should assess exposure and upgrade to version 3.41.3 or later to prevent unauthorized access to S3 credentials.

Why it matters

CVE-2026-54356 Budibase vulnerability allows authenticated users to obtain signed and public URLs backed by stored S3 credentials, requiring remediation to prevent unauthorized access.

  • Potential unauthorized access to S3 credentials
  • Possible misuse of signed and public URLs
  • Required verification of Budibase instance vulnerability
  • Necessity to restrict access to S3 datasources

Technical summary

Budibase open-source low-code platform vulnerability allows authenticated published-app users with the BASIC role to supply attacker-controlled bucket and key values and obtain signedUrl and publicUrl values backed by stored S3 datasource credentials. The issue is caused by insufficient input validation, allowing attackers to manipulate S3 credentials. This could lead to unauthorized access to sensitive data. The vulnerability is fixed in version 3.41.3, which enhances input validation and restricts unauthorized access.

Defensive priority

Remediate vulnerable Budibase instances to prevent unauthorized access to S3 credentials

Recommended defensive actions

  • Upgrade Budibase to version 3.41.3 or later
  • Review and restrict access to S3 datasources
  • Monitor for suspicious activity on Budibase instances
  • Verify the integrity of stored S3 credentials
  • Implement additional logging and monitoring for S3 interactions
  • Conduct a thorough review of Budibase instance configurations
  • whoShouldCare

Evidence notes

CVE and NVD records indicate vulnerability in Budibase versions prior to 3.41.3. Vendor provides fix in version 3.41.3. The vulnerability allows authenticated published-app users with the BASIC role to supply attacker-controlled bucket and key values and obtain signedUrl and publicUrl values backed by stored S3 datasource credentials. Evidence is based on CVE and NVD records, which detail the vulnerability and its fix.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-54356 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-54356

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-54356 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-54356

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.