What is CVE-2026-73617?
CVE-2026-73617 is a NoSQL injection vulnerability in Budibase versions before 3.40.0 within its MongoDB datasource integration. Attackers can inject MongoDB operators through user-supplied parameters that are enriched with handlebars using 'noEscaping: true' and lack operator filtering, potentially allowing query logic bypass. Upgrading to version 3.40.0 or later is required to mitigate this vulnerability.
Azərbaycanca: CVE-2026-73617, Budibase platformunun 3.40.0 versiyasından əvvəlki versiyalarında MongoDB məlumat mənbəyində aşkarlanmış NoSQL injection zəifliyidir. Təcavüzkar istifadəçi tərəfindən göndərilən parametrlər vasitəsilə MongoDB operatorlarını yeridərək, sorğu məntiqini manipulyasiya edə bilər. Bu problemi aradan qaldırmaq üçün Budibase proqramı ən azı 3.40.0 versiyasına yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: Budibase
FAQ2
Which versions of the Budibase platform are affected by CVE-2026-73617?
This vulnerability affects versions of the Budibase platform prior to 3.40.0.
How is CVE-2026-73617 exploited?
An attacker can inject MongoDB operators through user-supplied parameters to manipulate the query logic.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.