← Back to search

CVE-2026-100682

8.8 HIGHpublic exploit available

Published 2026-09-26 · Updated 2026-09-28

AI risk analysis

Summary
This vulnerability allows attackers with BUILDER role to write arbitrary files as root via a malicious ZIP archive, enabling remote code execution.
Exploitability
Exploitation requires an attacker to have BUILDER role and craft a specific ZIP archive, making it moderately hard to exploit.
Blast radius
If exploited, this could lead to full control of the server, including remote code execution, with severe consequences.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to Budibase Server 3.45.0 or later.
rcewebarbitrary-file-write

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon upload endpoint that extracts user-supplied ZIP archives without proper symlink validation. Attackers with BUILDER role can craft a malicious ZIP with leaf symlink entries followed by duplicate file entries to write arbitrary files as root, enabling remote code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-22

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.