A vulnerability labeled as critical has been found in Budibase up to 3.39.x . The impacted element is an unknown function of the component Export . Such manipulation leads to path traversal. This vulnerability is traded as CVE-2026-72850 . The attack may be launched remotely. There is no exploit available. The affected component should be upgraded.