V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2026-25737
ANC
Critical

Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.24.0 and earlier, an arbitrary file upload v…

CVSS
9.0
Critical
EPSS
0.00
p17
Published
2026-01-01
Updated
2026-01-01
Description

Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.24.0 and earlier, an arbitrary file upload vulnerability exists even though file extension restrictions are configured. The restriction is enforced only at the UI level. An attacker can bypass these restrictions and upload malicious files.

Tags · CWE
CWE-602
CAPEC-21
CAPEC-31
CAPEC-162
CAPEC-202
CAPEC-207
CAPEC-208
CAPEC-383
CAPEC-384
CAPEC-385
CAPEC-386
CAPEC-387
CAPEC-388
Affected products
Budibase ≤ 3.24.0
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Timeline
2026-01-01
Published
2026-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: R
Required (R)
Scope
S: C
Changed (C)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.003 · p17
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-383 · CWE-602
└ via CAPEC-21 · CWE-602
└ via CAPEC-21 · CWE-602
└ via CAPEC-21 · CWE-602
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
Tracked
budibase*Tracked