CVE-2026-35216
Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) o
CVSS
9.0
Critical
EPSS
12.0%
p96
KEV
—
Exploit Today
29
0-100
Published: Apr 3, 2026 · Last modified: Jul 24, 2026 · CWE-78
12.0%EPSS · 30 days12.0%
2026-07-012026-07-28
Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) on the Budibase server by triggering an automation that contains a Bash step via the public webhook endpoint. No authentication is required to trigger the exploit. The process executes as root inside the container. This issue has been patched in version 3.33.4.
- github.comhttps://github.com/Budibase/budibase/commit/f0c731b409a96e401445a6a6030d2994ff4ac256
- github.comhttps://github.com/Budibase/budibase/pull/18238
- github.comhttps://github.com/Budibase/budibase/releases/tag/3.33.4
- github.comhttps://github.com/Budibase/budibase/security/advisories/GHSA-fcm4-4pj2-m5hf
- github.comhttps://github.com/Budibase/budibase/security/advisories/GHSA-fcm4-4pj2-m5hf
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-674386.6 MED—
———OliveTin gives access to predefined shell commands from a web interface. From 3000.2.0 until 3000.17.0, the service/internal/executor/arguments.go checkShellArgumentSafety function does not treat regex: custom argument types as unsafe for Shell mode actions, allowing values that pass typeSafetyCheckRegex to be interpolated by wrapCommandInShell into an sh -c command string and enabling OS command injection. This issue is fixed in version 3000.17.0.10hCVE-2026-56389——
——0GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration variables. A grammar file can override the executable used for the XML‑to‑HTML transformation step via %define tool.xsltproc, which is accepted without restriction and passed directly to execvp().
When running bison --html on a attacker-provided grammar, this behavior allows execution of an arbitrary program with the privileges of the Bison process.
Maintainers of this project were notified about this vulnerability, and fixed the issue in commit 3169c1e7a2c6acc4c59dfcf8b089896d6881925b. However, they did not provide vulnerable version range. Version 3.8.2 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.18hCVE-2026-149599.1 CRI—
——0IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection.2hCVE-2026-149589.1 CRI—
——0IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation.2hCVE-2026-613767.2 HIG63.1%
——19ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.2dCVE-2026-597647.2 HIG63.1%
——19ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.2d