Budibase before 3.40.0 contains a SQL injection vulnerability in the Oracle datasource connector's post-write row lookup that fails to escape table names in identifiers. Attackers with write permission on a table with a double-quote in its name can inject SQL that executes as the datasource's database user to read or modify arbitrary data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 13 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Budibase before 3.40.0 contains a SQL injection vulnerability in the Oracle datasource connector's post-write row lookup that fails to escape table names in identifiers. Attackers with write permission on a table with a double-quote in its name can inject SQL that executes as the datasource's database user to read or modify arbitrary data. | |
| Title | Budibase before 3.40.0 SQL Injection via Oracle connector | |
| First Time appeared |
Budibase
Budibase budibase |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:budibase:budibase:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Budibase
Budibase budibase |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-13T21:54:43.945Z
Reserved: 2026-08-10T15:16:31.371Z
Link: CVE-2026-72853
No data.
Status : Received
Published: 2026-08-13T22:17:24.593
Modified: 2026-08-13T22:17:24.593
Link: CVE-2026-72853
No data.
OpenCVE Enrichment
No data.
Weaknesses