CVE-2026-72853
- EPSS 0.25%
- Veröffentlicht 13.08.2026 21:54:43
- Zuletzt bearbeitet 18.08.2026 02:17:28
Budibase before 3.40.0 contains a SQL injection vulnerability in the Oracle datasource connector's post-write row lookup that fails to escape table names in identifiers. Attackers with write permission on a table with a double-quote in its name can i...
CVE-2026-73409
- EPSS 0.19%
- Veröffentlicht 12.08.2026 19:19:59
- Zuletzt bearbeitet 14.08.2026 22:17:11
Budibase is an open-source low-code platform. Prior to 3.40.1, packages/server/src/integrations/mongodb.ts passed builder-controlled tlsCertificateKeyFile and tlsCAFile values directly to MongoClient on Budibase Cloud. A builder could submit absolute...
- EPSS 0.42%
- Veröffentlicht 12.08.2026 19:09:55
- Zuletzt bearbeitet 12.08.2026 20:17:55
Budibase is an open-source low-code platform. Prior to 3.40.1, RestIntegration._req in packages/server/src/integrations/rest.ts attached credentials from getAuthHeaders and defaultHeaders without requiring the final request destination to match the d...
CVE-2026-73406
- EPSS 0.37%
- Veröffentlicht 12.08.2026 19:03:51
- Zuletzt bearbeitet 13.08.2026 15:20:13
Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/users/tenant/:id was listed in PUBLIC_ENDPOINTS in packages/worker/src/api/index.ts, and tenantUserLookup returned a full PlatformUser document. An unauthenticated caller...
CVE-2026-73308
- EPSS 0.29%
- Veröffentlicht 12.08.2026 19:01:15
- Zuletzt bearbeitet 14.08.2026 22:17:10
Budibase is an open-source low-code platform. Prior to 3.39.25, packages/server/src/api/controllers/automation.ts returned automation test results containing trigger.outputs.user.oauth2, broadcast BuilderSocketEvent.AutomationTestProgress to the app ...
CVE-2026-73307
- EPSS 0.31%
- Veröffentlicht 12.08.2026 18:59:52
- Zuletzt bearbeitet 12.08.2026 20:17:54
Budibase is an open-source low-code platform. Prior to 3.39.4, uploadUrl in packages/server/src/utilities/fileUtils.ts used a bare server-side fetch for string attachment values passed by processAttachments in packages/server/src/sdk/workspace/ai/hel...
CVE-2026-73306
- EPSS 0.32%
- Veröffentlicht 12.08.2026 18:56:08
- Zuletzt bearbeitet 13.08.2026 13:19:17
Budibase is an open-source low-code platform. Prior to 3.39.25, POST /api/global/auth/:tenantId/login incremented the failure counter in packages/worker/src/api/controllers/global/auth.ts only for existing users, while packages/worker/src/middleware/...
CVE-2026-73303
- EPSS 0.23%
- Veröffentlicht 12.08.2026 18:51:38
- Zuletzt bearbeitet 12.08.2026 23:17:24
Budibase is an open-source low-code platform. Prior to 3.40.0, POST /api/v2/email on account.budibase.app accepted a client-controlled accountId without binding it to the authenticated session, while checking only currentEmail. An authenticated attac...
CVE-2026-73301
- EPSS 0.25%
- Veröffentlicht 12.08.2026 18:08:07
- Zuletzt bearbeitet 14.08.2026 22:17:10
Budibase is an open-source low-code platform. Prior to 3.39.25, the GET /api/global/groups endpoint in packages/worker/src/api/routes/global/groups.ts omitted auth.builderOrAdmin, allowing an authenticated BASIC role user to enumerate tenant groups, ...
CVE-2026-73300
- EPSS 0.38%
- Veröffentlicht 12.08.2026 18:05:51
- Zuletzt bearbeitet 12.08.2026 20:17:54
Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: true, enabling execution of multiple SQL statements in a single query. Attackers can inject malicious SQ...