SQL Injection Vulnerability in Budibase Oracle Datasource Connector
CVE-2026-72853

8.8HIGH

Key Information:

Vendor

Budibase

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-72853?

Budibase versions prior to 3.40.0 are affected by a SQL injection vulnerability in the Oracle datasource connector. This vulnerability arises from improper escaping of table names in SQL identifiers during the post-write row lookup process. An attacker with write permissions on a table that includes a double-quote in its name can inject malicious SQL code that executes as the database user of the datasource. This can lead to unauthorized data access or modifications, making it crucial for users to update to the latest version to mitigate risks.

Affected Version(s)

budibase 0 < 3.40.0

budibase 3.40.0

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

dizconnectz
.