Unauthenticated SQL Injection Vulnerability in Budibase Products by Budibase
CVE-2026-72851
9CRITICAL
What is CVE-2026-72851?
Budibase, a platform for building applications, is vulnerable to an unauthenticated SQL injection flaw found in webhook-triggered automations. Attackers can exploit this weakness by sending specially crafted JSON payloads to the webhook trigger endpoint, allowing them to execute arbitrary SQL commands using the database credentials configured by the builder. This vulnerability opens the door for unauthorized data access, manipulation, and potential long-term persistence within connected data sources such as Snowflake. Users are advised to update to version 3.40.0 or later to mitigate this risk.
Affected Version(s)
server 0 < 3.40.0
server 3.40.0
