Budibase disclosed seven vulnerabilities affecting versions before 3.40.0, including CVE-2026-72851, a maximum-severity unauthenticated SQL injection in webhook-triggered automations that use EXECUTE_QUERY steps. The flaw lets attackers send crafted JSON to public webhook endpoints and run SQL with builder-configured database credentials, creating a path to data theft, unauthorized modification, and persistence in connected data sources such as Snowflake. Budibase said version 3.40.0 remediates the issues and reported no known active exploitation at publication time.
The disclosure also includes CVE-2026-73300, a MySQL SQL injection tied to multipleStatements: true, and CVE-2026-72853, an Oracle connector SQL injection in post-write row lookup caused by improper escaping of table names. Additional issues reportedly exposed plaintext MongoDB connection strings and Firebase private keys through the datasource API, enabled cross-workspace automation execution, introduced AI table-generation SSRF, and allowed arbitrary file write via path traversal. Organizations running Budibase were urged to upgrade to 3.40.0, rotate potentially exposed MongoDB and Firebase credentials, and review webhook exposure and database permissions.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
A new CVE, CVE-2026-73410, was received on August 17, 2026 for an SSRF flaw in Budibase's REST datasource integration caused by DNS rebinding after outbound address validation. The issue affects versions earlier than 3.40.0 and allows an authenticated builder to reach internal addresses, access full responses, and send arbitrary REST methods; Budibase fixed it in version 3.40.0.
A new CVE, CVE-2026-72859, was received on August 14, 2026 for an authorization regression in Budibase Server's S3 attachment upload endpoint. The flaw affects versions 3.39.4 before 3.40.0 and allows BASIC users to obtain S3 PutObject presigned URLs and perform unauthorized file uploads to buckets reachable by stored IAM credentials.
CVE-2026-72853 was received on August 13, 2026 for a SQL injection flaw in Budibase's Oracle datasource connector post-write row lookup. The issue affects versions before 3.40.0 and can let an attacker with write permission inject SQL as the datasource database user.
CVE-2026-72851 was received on Aug. 13, 2026 for an unauthenticated SQL injection in Budibase webhook-triggered automations using `EXECUTE_QUERY` steps. The flaw affects Budibase Server versions before 3.40.0 and can enable data exfiltration, modification, and persistence in connected datasources.
A new CVE, CVE-2026-73300, was received on Aug. 12, 2026 for a SQL injection flaw in Budibase's MySQL integration caused by `multipleStatements: true`. The issue affects versions earlier than 3.40.0 and can allow malicious SQL execution through user input fields.
Budibase disclosed seven vulnerabilities affecting versions before 3.40.0, including CVE-2026-72851, CVE-2026-73300, CVE-2026-72853, CVE-2026-54351, GHSA-6mpp-gfg5-x2vv, an arbitrary file write issue, and CVE-2026-73307. The disclosure stated that version 3.40.0 addresses all seven issues and that there was no known active exploitation at the time of publication.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
7 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcethreataft.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcevulncheck.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.