PT-2026-99354 · Budibase · Budibase

·

CVE-2026-100683

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v4.0

8.9

High

VectorAV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Budibase (@budibase/server) versions prior to 3.45.0
Description An issue exists in the way MySQL and MSSQL column-rename DDL is constructed in packages/backend-core/src/sql/sqlTable.ts. The software interpolates identifiers directly into a raw query string without using the quoteMySqlIdentifier or quoteSqlServerIdentifier helpers. An attacker with DDL rights on a connected datasource can create a column name containing a backtick for MySQL or a single quote for MSSQL, followed by malicious SQL. When a user renames this column via the UI using the 'POST /api/tables' endpoint with the rename.old parameter, the injected SQL is executed. In MySQL environments, the use of multipleStatements: true allows the execution of stacked statements, enabling arbitrary reads, writes, or destructive operations on the connected database, bypassing the row and table permission model.
Recommendations Update Budibase (@budibase/server) to version 3.45.0.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100683
GHSA-PPJ8-HMX2-M546

Affected Products

Budibase