What is CVE-2026-73408?
A SQL injection vulnerability exists in the MySQL integration of the open-source low-code platform Budibase prior to version 3.39.18. An attacker could execute unvalidated statements by creating a MySQL table with a backtick and stacked statement in its name, due to unsanitized table names and enabled `multipleStatements`. Users should immediately upgrade to version 3.39.18 or later.
Azərbaycanca: Budibase açıq mənbəli low-code platformasının 3.39.18-dən əvvəlki versiyalarında MySQL inteqrasiyasında SQL injection zəifliyi aşkar edilib. Təcavüzkar, adında backtick (`) və stacked statement olan MySQL cədvəli yaradaraq təsdiqlənməmiş əmrlər icra edə bilər. İstifadəçilərə dərhal 3.39.18 və ya daha yuxarı versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ1
Which versions of Budibase are affected by the CVE-2026-73408 SQL injection vulnerability?
Budibase versions prior to 3.39.18 are affected by this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.