Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 13 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Budibase before 3.40.0 contains a SQL injection vulnerability in the Oracle datasource connector's post-write row lookup that fails to escape table names in identifiers. Attackers with write permission on a table with a double-quote in its name can inject SQL that executes as the datasource's database user to read or modify arbitrary data. | |
| Title | Budibase before 3.40.0 SQL Injection via Oracle connector | |
| First Time appeared |
Budibase
Budibase budibase |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:budibase:budibase:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Budibase
Budibase budibase |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-13T21:54:43.945Z
Reserved: 2026-08-10T15:16:31.371Z
Link: CVE-2026-72853
No data.
Status : Received
Published: 2026-08-13T22:17:24.593
Modified: 2026-08-13T22:17:24.593
Link: CVE-2026-72853
No data.
OpenCVE Enrichment
Updated: 2026-08-14T00:45:17Z