What is CVE-2026-72853?
CVE-2026-72853 is an SQL injection vulnerability found in Budibase versions prior to 3.40.0 within the Oracle datasource connector's post-write row lookup, caused by improper escaping of table names in identifiers. An attacker with write permissions can leverage a table name containing a double-quote to inject and execute arbitrary SQL commands as the datasource's database user. Upgrading to version 3.40.0 or later is strongly recommended to mitigate this issue.
Azərbaycanca: CVE-2026-72853, Budibase platformunun 3.40.0 versiyasından əvvəlki versiyalarında Oracle məlumat mənbəyi birləşdiricisində aşkarlanmış SQL injection zəifliyidir. Bu zəiflik, yazma icazəsi olan hücumçulara cədvəl adlarında dırnaq işarəsindən istifadə etməklə verilənlər bazası səviyyəsində SQL sorğularını icra etməyə imkan verir. Problemi aradan qaldırmaq üçün dərhal 3.40.0 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: Budibase
FAQ2
What level of permissions does an attacker need to exploit CVE-2026-72853?
To exploit this SQL injection vulnerability, an attacker must have write permissions within the Budibase platform.
What version is recommended to mitigate CVE-2026-72853?
It is strongly recommended to upgrade Budibase to version 3.40.0 or later to mitigate this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.