CVE-2026-35214 | budibase up to 3.33.3 Plugin File Upload Endpoint /api/plugin/upload createTempFolder path traversal
A vulnerability classified as critical was found in budibase up to 3.33.3. Affected by this issue is the function createTempFolder of the file /api/plugin/upload of the component Plugin File Upload Endpoint. Executing a manipulation can lead to path traversal.
This vulnerability is registered as CVE-2026-35214. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.