CVE-2026-54356 | Budibase up to 3.41.2 Attachments static.ts bucket/key privileges management

SecurityVulns

A vulnerability identified as critical has been detected in Budibase up to 3.41.2. This affects an unknown function of the file packages/server/src/api/routes/static.ts of the component Attachments. The manipulation of the argument bucket/key leads to improper privilege management.

This vulnerability is documented as CVE-2026-54356. The attack can be initiated remotely. There is not any exploit available.

You should upgrade the affected component.VulDB Recent EntriesRead More