PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72851 budibase CVE debrief

Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers can POST attacker-controlled JSON to the webhook trigger endpoint to inject SQL payloads that execute with builder-configured database credentials, enabling data exfiltration, modification, and persistence in connected datasources like Snowflake.

Vendor
budibase
Product
server
CVSS
CRITICAL 9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-13
Original CVE updated
2026-08-31
Advisory published
2026-08-13
Advisory updated
2026-08-31

Who should care

Security teams and administrators responsible for Budibase installations should be aware of this vulnerability and take immediate action to mitigate the risk. They should verify Budibase versions, review webhook configurations, and monitor for suspicious activity. Additional security measures should be implemented to protect connected datasources like Snowflake. IT teams and developers who use Budibase should also be aware of the vulnerability and take necessary precautions to protect their applications and data. Furthermore, vulnerability management teams should prioritize patching Budibase installations to prevent potential data breaches and unauthorized access to sensitive information. Security teams should also review their incident response plans to ensure they are prepared to respond to potential attacks exploiting this vulnerability. Additionally, administrators should consider implementing compensating controls, such as web application firewalls, to detect and prevent SQL injection attacks. By taking these steps, organizations can reduce the risk associated with this vulnerability and protect their sensitive data and applications. Budibase users should also consider reviewing their system logs and monitoring for suspicious activity to detect potential attacks. Moreover, security teams should assess their current security posture and identify areas for improvement to prevent similar vulnerabilities in the future. Finally, IT teams should prioritize patching and updating Budibase installations to prevent exploitation of this vulnerability and ensure the security of their applications and data. The vulnerability's critical CVSS score and potential for significant data compromise make it essential for security teams to take immediate action to mitigate the risk. Budibase users should verify their versions and upgrade to 3.40.0 or later as soon as possible to prevent exploitation of this vulnerability. In addition, security teams should review their vulnerability management processes to ensure they are equipped to handle similar vulnerabilities in the future. By prioritizing patching, monitoring, and compensating controls, organizations can reduce the risk of

Technical summary

CVE-2026-72851 is a critical SQL injection vulnerability in Budibase versions before 3.40.0. The vulnerability occurs in webhook-triggered automations with EXECUTE_QUERY steps, allowing attackers to inject SQL payloads with attacker-controlled JSON. This could lead to data exfiltration, modification, and persistence in connected datasources. Security teams should be aware of the vulnerability and take immediate action to mitigate the risk.

Defensive priority

High priority due to critical CVSS score and potential for significant data compromise.

Recommended defensive actions

  • Verify Budibase version and upgrade to 3.40.0 or later
  • Review webhook-triggered automations for EXECUTE_QUERY steps
  • Restrict access to webhook trigger endpoints
  • Monitor for suspicious database activity
  • Implement additional security measures to protect connected datasources

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. Further verification is recommended. Budibase versions before 3.40.0 are affected by an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Security teams should verify Budibase installations, review webhook configurations, and monitor for suspicious activity. Additional security measures should be implemented to protect connected datasources like Snowflake.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72851 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72851

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72851 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72851

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.