CVE-2026-54356: Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url`
Summary Budibase 3.39.7 allows a low-privilege authenticated published-app user with the built-in BASIC role to obtain arbitrary S3 pre-signed upload URLs backed by a workspace datasource's stored server-side credentials.
The affected endpoint is:
POST /api/attachments/:datasourceId/url
The caller can control: text bucket key and receives: text signedUrl publicUrl
This lets a low-privilege published-app user mint S3 PUT URLs using server-side datasource credentials for attacker-chosen object destinations.
Steps:
1. Log in as an admin user. 2. Create a new app/workspace. 3. In the development app context, create an S3 datasource with valid credentials. 4. Publish the app. 5. Create a low-privilege user with the built-in BASIC role on the published production app ID. 6. Log in as that BASIC user. 7. Send: POST /api/attachments/<datasourceId>/url
with: json {"bucket":"foo","key":"bar"} and the published app header: text x-budibase-app-id: <publishedappid> Observe a successful response containing: text signedUrl publicUrl
Observed result
The following behavior:
dev BASIC request: 403 User does not have permission app publish: SUCCESS prod BASIC request: 200 OK Example confirmed runtime values from the final successful run: text prodAppId: appe6b4cdc6cd6949969a83ff11eee88c5a datasourceId: datasource0cec491b26a742468257c62382aa3284 publicUrl: https://foo.s3.eu-west-1.amazonaws.com/bar The returned signedUrl contained standard AWS signing markers, including: text X-Amz-Credential=bb X-Amz-Signature X-Amz-Expires=900 Impact
A low-privilege published-app user who knows a valid datasource ID can mint S3 upload URLs backed by server-side datasource credentials and choose arbitrary destination bucket and key values.
Route definition packages/server/src/api/routes/static.ts:45 Authorization logic packages/server/src/middleware/authorized.ts packages/server/src/middleware/resourceId.ts Controller logic packages/server/src/api/controllers/static/index.ts Datasource lookup packages/server/src/sdk/workspace/datasources/datasources.ts
Other sources
Budibase is an open-source low-code platform. Prior to 3.41.3, POST /api/attachments/:datasourceId/url in packages/server/src/api/routes/static.ts and packages/server/src/api/controllers/static/index.ts allows an authenticated published-app user with the BASIC role to supply attacker-controlled bucket and key values and obtain signedUrl and publicUrl values backed by stored S3 datasource credentials. This issue is fixed in version 3.41.3.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Budibaseto a version that resolves this vulnerability.Fixed in 3.41.3 - Compensating control
If you cannot immediately upgrade to Budibase 3.41.3, restrict the published-app user’s ability to use the endpoint POST /api/attachments/:datasourceId/url (e.g., remove/limit BASIC role permissions for the affected published app route or datasource access) so low-privilege users cannot mint S3 pre-signed upload URLs with attacker-controlled bucket/key.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-54356?
CVE-2026-54356 has a high severity rating of 7.1.
How do I fix CVE-2026-54356?
To fix CVE-2026-54356, update Budibase to version 3.41.3 or later.
What is the risk score of CVE-2026-54356?
CVE-2026-54356 has a risk score of 48.
Who is affected by CVE-2026-54356?
CVE-2026-54356 affects authenticated users with the BASIC role in Budibase prior to version 3.41.3.
What type of vulnerability is CVE-2026-54356?
CVE-2026-54356 is an authenticated arbitrary S3 signed upload URL issuance vulnerability.