PT-2026-71908 · Budibase+1 · Budibase+1

·

CVE-2026-72851

·

Published

2026-08-13

·

Updated

2026-08-13

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Budibase versions prior to 3.40.0
Description An unauthenticated SQL injection exists in webhook-triggered automations that utilize EXECUTE QUERY steps. An attacker can send a POST request containing malicious JSON to the webhook trigger endpoint to inject SQL payloads. These payloads execute using the database credentials configured by the builder, which may allow for data exfiltration, modification, and the establishment of persistence within connected datasources, such as Snowflake.
Recommendations Update Budibase to version 3.40.0 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72851
GHSA-X7H8-WW3Q-XV7C

Affected Products

Budibase
Snowflake