CVE-2026-54356: Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url`

Published Aug 17, 2026
·
Updated

Summary Budibase 3.39.7 allows a low-privilege authenticated published-app user with the built-in BASIC role to obtain arbitrary S3 pre-signed upload URLs backed by a workspace datasource's stored server-side credentials.

The affected endpoint is:

POST /api/attachments/:datasourceId/url

The caller can control: text bucket key and receives: text signedUrl publicUrl

This lets a low-privilege published-app user mint S3 PUT URLs using server-side datasource credentials for attacker-chosen object destinations.

Steps:

1. Log in as an admin user. 2. Create a new app/workspace. 3. In the development app context, create an S3 datasource with valid credentials. 4. Publish the app. 5. Create a low-privilege user with the built-in BASIC role on the published production app ID. 6. Log in as that BASIC user. 7. Send: POST /api/attachments/<datasourceId>/url

with: json {"bucket":"foo","key":"bar"} and the published app header: text x-budibase-app-id: <publishedappid> Observe a successful response containing: text signedUrl publicUrl

Observed result

The following behavior:

dev BASIC request: 403 User does not have permission app publish: SUCCESS prod BASIC request: 200 OK Example confirmed runtime values from the final successful run: text prodAppId: appe6b4cdc6cd6949969a83ff11eee88c5a datasourceId: datasource0cec491b26a742468257c62382aa3284 publicUrl: https://foo.s3.eu-west-1.amazonaws.com/bar The returned signedUrl contained standard AWS signing markers, including: text X-Amz-Credential=bb X-Amz-Signature X-Amz-Expires=900 Impact

A low-privilege published-app user who knows a valid datasource ID can mint S3 upload URLs backed by server-side datasource credentials and choose arbitrary destination bucket and key values.

Route definition packages/server/src/api/routes/static.ts:45 Authorization logic packages/server/src/middleware/authorized.ts packages/server/src/middleware/resourceId.ts Controller logic packages/server/src/api/controllers/static/index.ts Datasource lookup packages/server/src/sdk/workspace/datasources/datasources.ts

Other sources

Budibase is an open-source low-code platform. Prior to 3.41.3, POST /api/attachments/:datasourceId/url in packages/server/src/api/routes/static.ts and packages/server/src/api/controllers/static/index.ts allows an authenticated published-app user with the BASIC role to supply attacker-controlled bucket and key values and obtain signedUrl and publicUrl values backed by stored S3 datasource credentials. This issue is fixed in version 3.41.3.

— NVD

Affected Software

2 affected components
budibase Budibase<3.41.3
npm/@budibase/server<=3.38.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Budibase to a version that resolves this vulnerability.

    Fixed in 3.41.3
  2. Compensating control

    If you cannot immediately upgrade to Budibase 3.41.3, restrict the published-app user’s ability to use the endpoint POST /api/attachments/:datasourceId/url (e.g., remove/limit BASIC role permissions for the affected published app route or datasource access) so low-privilege users cannot mint S3 pre-signed upload URLs with attacker-controlled bucket/key.

Event History

Aug 17, 2026
CVE Published
via MITRE·08:32 PM
Data Sourced
via MITRE·08:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Aug 26, 2026
Advisory Published
via GitHub·02:07 PM
Data Sourced
via GitHub·02:07 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-54356?

CVE-2026-54356 has a high severity rating of 7.1.

2

How do I fix CVE-2026-54356?

To fix CVE-2026-54356, update Budibase to version 3.41.3 or later.

3

What is the risk score of CVE-2026-54356?

CVE-2026-54356 has a risk score of 48.

4

Who is affected by CVE-2026-54356?

CVE-2026-54356 affects authenticated users with the BASIC role in Budibase prior to version 3.41.3.

5

What type of vulnerability is CVE-2026-54356?

CVE-2026-54356 is an authenticated arbitrary S3 signed upload URL issuance vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203