SQL Injection Vulnerability in Budibase Low-Code Platform
CVE-2026-73300

9.6CRITICAL

Key Information:

Vendor

Budibase

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-73300?

The Budibase low-code platform is susceptible to SQL injection due to its MySQL integration component, which is configured to allow multiple SQL statements in a single query. This configuration permits attackers to manipulate user inputs and execute arbitrary SQL commands, which can lead to a complete compromise of the underlying database. A security fix was implemented in version 3.40.0, ensuring that SQL injection risks are mitigated.

Affected Version(s)

budibase < 3.40.0

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.