Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.0

CVE-2026-72851: Budibase before 3.40.0: Unauthenticated SQL Injection via Webhook

CVE-2026-72851 · published 21 days ago
Summary

Budibase, a low-code platform, has a security issue that allows attackers to inject malicious SQL code without being authenticated. This could lead to sensitive data being stolen, modified, or permanently changed in connected databases. To protect your data, update Budibase to version 3.40.0 or later.

What to do
  • Update budibase server to version 3.40.0 or later.
Affected software
VendorProductAffected versions
budibase server < 3.40.0
Original advisory text
Budibase before 3.40.0 SQL Injection via Unauthenticated Webhook
Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers can POST attacker-controlled JSON to the webhook trigger endpoint to inject SQL payloads that execute with builder-configured database credentials, enabling data exfiltration, modification, and persistence in connected datasources like Snowflake.
Severity
9.0 Critical
CVSS 3.1: 10.0 (NVD)
CVSS 4.0: 9.0 (NVD)
CVSS 4.0: 8.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-89SQL Injection
Timeline
Published13 Aug 2026
Updated29 Aug 2026
First seen13 Aug 2026
Sources
CVE-2026-72851 · MITRE
Monitor software like this
Free during beta