What is CVE-2026-64657?
CVE-2026-64657 is a vulnerability in the Budibase open-source low-code platform where the PostgreSQL datasource connector improperly interpolates user-controlled schema configuration into a SET search_path statement without escaping double quotes. This allows an authenticated attacker to perform SQL injection via a crafted schema field. Users should urgently upgrade to version 3.39.19 or later.
Azərbaycanca: Budibase açıq mənbəli low-code platformasında aşkar edilmiş CVE-2026-64657 zəifliyi PostgreSQL datasource connector-da schema konfiqurasiya sahəsinin düzgün təmizlənməməsi nəticəsində SQL injection-a yol açır. Bu, autentifikasiya olunmuş istifadəçiyə xüsusi hazırlanmış schema dəyəri ilə SET search_path əmrini manipulyasiya etməyə imkan verir. İstifadəçilər 3.39.19 və daha yuxarı versiyaya təcili yeniləmə etməlidir.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which component of the Budibase platform is affected by CVE-2026-64657?
This vulnerability affects the PostgreSQL datasource connector component in Budibase, where the schema configuration field is not properly sanitized.
What security risk arises from exploiting CVE-2026-64657?
This vulnerability allows an authenticated attacker to perform SQL injection by manipulating the SET search_path statement via a crafted schema field.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.