Unauthenticated SQL Injection Vulnerability in Budibase Products by Budibase
CVE-2026-72851

9CRITICAL

Key Information:

Vendor

Budibase

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-72851?

Budibase, a platform for building applications, is vulnerable to an unauthenticated SQL injection flaw found in webhook-triggered automations. Attackers can exploit this weakness by sending specially crafted JSON payloads to the webhook trigger endpoint, allowing them to execute arbitrary SQL commands using the database credentials configured by the builder. This vulnerability opens the door for unauthorized data access, manipulation, and potential long-term persistence within connected data sources such as Snowflake. Users are advised to update to version 3.40.0 or later to mitigate this risk.

Affected Version(s)

server 0 < 3.40.0

server 3.40.0

References

CVSS V4

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hypnguyen1209
.