---
id: CVE-2026-72859
title: >-
  Budibase versions 3.39.4 before 3.40.0 contain an authorization regression in
  the S3 attachment upload endpoint that allows BASIC users to obtain S3
  PutObject presigned URLs by sending POST requests to the attachments endpoint
summary: >-
  Budibase versions 3.39.4 before 3.40.0 contain an authorization regression in
  the S3 attachment upload endpoint that allows BASIC users to obtain S3
  PutObject presigned URLs by sending POST requests to the attachments endpoint.
  The route…
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N'
cwe:
  - CWE-863
vendor: budibase
product: server
affected:
  - server >= 3.39.4 < 3.40.0
published: '2026-08-14'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:37.227'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-72859'
references:
  - url: >-
      https://github.com/Budibase/budibase/security/advisories/GHSA-xcx6-4f2g-hhgx
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/budibase-before-authorization-regression-via-s3-presigned-url
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Budibase/budibase/security/advisories/GHSA-xcx6-4f2g-hhgx
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-14T14:39:18.513836Z'
epss: 0.00311
epssPercentile: 0.21987
ingestedAt: '2026-10-08T16:52:14.718Z'
---

## Overview

Budibase versions 3.39.4 before 3.40.0 contain an authorization regression in the S3 attachment upload endpoint that allows BASIC users to obtain S3 PutObject presigned URLs by sending POST requests to the attachments endpoint. The route was changed from a BUILDER permission check to a TABLE/WRITE check, which BASIC users hold by default. Attackers can specify arbitrary S3 buckets in the request body to generate presigned URLs for writing to any bucket accessible by the stored IAM credentials, enabling unauthorized file uploads.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
