SQL Injection Vulnerability in Budibase Low-Code Platform
CVE-2026-64657

8.4HIGH

Key Information:

Vendor

Budibase

Status
Vendor
CVE Published:
17 August 2026

What is CVE-2026-64657?

The Budibase low-code platform, up to version 3.39.19, contains a SQL injection vulnerability in its PostgreSQL datasource connector. An authenticated administrator can exploit this weakness by saving or testing the datasource, allowing for the execution of arbitrary SQL commands through the simple query protocol. The vulnerability arises from the interpolation of user-controlled schema configuration fields into a SET search_path statement, where embedded double quotes are not properly escaped. This oversight can lead to significant security risks and potential unauthorized access to the database.

Affected Version(s)

budibase < 3.39.19

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.