Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

A critical authentication bypass vulnerability (CVE-2026-31816, CVSS 9.8) in Budibase, a low-code platform used to build internal business tools, allows unauthenticated attackers to access any API endpoint without credentials. A public reverse shell exploit (CVE-2026-31816-rshell) is available on GitHub and CISA has confirmed active exploitation in the wild. Any organization running Budibase 3.31.4 or earlier with internet-facing deployments faces immediate risk of full system compromise.

Author

Tech Jacks Solutions