PT-2026-84595 · Baserow · Baserow

·

CVE-2026-19754

·

Published

2026-09-02

·

Updated

2026-09-02

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Baserow version 2.3.3
Description An issue exists in the index() formula function where a low-privileged authenticated user with permissions to create or modify formula fields can provide an undocumented fourth argument. This argument is treated as a SQL template and interpolated directly into a PostgreSQL expression. The injected SQL is executed with the privileges of the Baserow PostgreSQL role during the recalculation of formula field values, bypassing the permissions of the authenticated application user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19754

Affected Products

Baserow