What is CVE-2026-72851?
Budibase versions before 3.40.0 contain an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers can send crafted JSON to the webhook trigger endpoint to inject SQL payloads that execute using builder-configured database credentials. Immediate update to version 3.40.0 or later is strongly advised to mitigate this risk.
Azərbaycanca: Budibase platformasının 3.40.0-dan əvvəlki versiyalarında, webhook-triggered automations funksiyasında autentifikasiya tələb etməyən SQL injection zəifliyi aşkar edilib. Hücumçular, webhook trigger endpoint-ə xüsusi hazırlanmış JSON göndərərək SQL payload-larını icra edə bilərlər. Sisteminizi qorumaq üçün dərhal Budibase-i 3.40.0 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: Budibase
FAQ2
Which versions of Budibase are affected by CVE-2026-72851?
The vulnerability affects Budibase versions before 3.40.0.
How can I protect my system from CVE-2026-72851?
Immediately update Budibase to version 3.40.0 or later to mitigate this risk.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.