SQL Injection Vulnerability in Baserow 2.3.3 by Baserow
CVE-2026-19754

8.6HIGH

Key Information:

Vendor

Baserow

Status
Vendor
CVE Published:
2 September 2026

What is CVE-2026-19754?

Baserow 2.3.3 has a SQL injection vulnerability found within the index() formula function. This flaw allows low-privileged authenticated users to inject malicious SQL code by providing an undocumented fourth argument. This argument is parsed as a SQL template and executed directly within PostgreSQL, using the database connection privileges of the Baserow PostgreSQL role, rather than those of the authenticated user. Consequently, this vulnerability can lead to unauthorized data access and manipulation within the Baserow application.

Affected Version(s)

Baserow Windows 2.3.3

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Miguel GĂłmez
Fluid Attacks' AI SAST Scanner
.