SQL Injection Vulnerability in Budibase Oracle Datasource Connector
CVE-2026-72853
8.8HIGH
What is CVE-2026-72853?
Budibase versions prior to 3.40.0 are affected by a SQL injection vulnerability in the Oracle datasource connector. This vulnerability arises from improper escaping of table names in SQL identifiers during the post-write row lookup process. An attacker with write permissions on a table that includes a double-quote in its name can inject malicious SQL code that executes as the database user of the datasource. This can lead to unauthorized data access or modifications, making it crucial for users to update to the latest version to mitigate risks.
Affected Version(s)
budibase 0 < 3.40.0
budibase 3.40.0
