PT-2026-71909 · Budibase+1 · Budibase+1

·

CVE-2026-72853

·

Published

2026-08-13

·

Updated

2026-08-18

CVSS v4.0

8.8

High

VectorAV:N/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Budibase versions prior to 3.40.0
Description A SQL injection issue exists in the Oracle datasource connector during the post-write row lookup process. The system fails to properly escape table names used in identifiers. An attacker with write permissions on a table containing a double-quote in its name can inject SQL commands. These commands execute with the privileges of the datasource database user, allowing the attacker to read or modify arbitrary data.
Recommendations Update to version 3.40.0 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72853
GHSA-XJ29-X47G-9W2C

Affected Products

Budibase
Oracle