VYPR
Vypr IntelligenceAI-generatedAug 14, 2026· 24 CVEs

Budibase: 24 Vulnerabilities Including SQLi, SSRF, and Auth Bypass Disclosed Together

A batch of 24 vulnerabilities, including critical flaws like SQL injection and SSRF, were disclosed for the Budibase low-code platform between August 12-14, 2026.

Key findings

  • 24 vulnerabilities disclosed for Budibase between August 12-14, 2026, affecting versions prior to 3.40.0.
  • Critical flaws include SQL injection, NoSQL injection, SSRF, and authorization bypasses.
  • Patches are available in Budibase versions 3.40.0 and 3.40.1.
  • Vulnerabilities span multiple integrations like MySQL, MongoDB, and REST API components.
  • Users are urged to update immediately to mitigate risks of data breaches and unauthorized access.

On August 12-14, 2026, a significant batch of 24 vulnerabilities was disclosed for the Budibase open-source low-code platform. These vulnerabilities, spanning critical to medium severity, were reported across various components of the Budibase server and integrations, with many fixed in version 3.40.0 or 3.40.1. The disclosures highlight a range of security weaknesses, including SQL injection, NoSQL injection, SSRF, authorization bypasses, and improper credential handling, underscoring the need for users to update promptly.

Several vulnerabilities center around injection flaws. CVE-2026-73408 and CVE-2026-73300 detail SQL injection risks in the MySQL integration, allowing attackers to execute arbitrary SQL commands by exploiting the multipleStatements: true configuration. Similarly, CVE-2026-73618 and CVE-2026-73617 describe NoSQL injection vulnerabilities in the MongoDB integration, where improper sanitization of user-supplied parameters can lead to unauthorized data access or manipulation. CVE-2026-72853 also presents a SQL injection risk within the Oracle datasource connector.

Authorization and authentication bypasses form another significant theme. CVE-2026-72856 describes an authorization bypass in the changeTenantOwnerEmail endpoint, allowing unauthorized users to change the tenant owner's email on self-hosted instances. CVE-2026-73305 points to an authorization regression in the role assignment API, enabling app-scoped builders to escalate privileges. Furthermore, CVE-2026-73407 details an unauthenticated vulnerability in the REST integration, allowing attackers to execute queries against any datasource using builder-configured credentials. CVE-2026-73406, an unauthenticated information disclosure, allows enumeration of users and tenant groups.

Server-Side Request Forgery (SSRF) and related network request vulnerabilities are also present. CVE-2026-35219 highlights an SSRF flaw in various automation steps (Webhook, Zapier, Slack, Discord, etc.), bypassing IP blacklist protections. CVE-2026-72855 describes SSRF vulnerabilities in OpenAPI query import and REST query execution, allowing authenticated users to bypass DNS pinning through DNS rebinding attacks. CVE-2026-73409 involves insecure handling of TLS certificate file paths in the MongoDB integration, potentially allowing unauthorized access to sensitive files.

Other notable vulnerabilities include improper handling of sensitive data and file path traversal. CVE-2026-72859 details an authorization regression in the S3 attachment upload endpoint, allowing basic users to obtain S3 presigned URLs. CVE-2026-72850 describes a file path traversal vulnerability in S3 object key handling during workspace export, enabling arbitrary file writes. CVE-2026-72851, a critical unauthenticated SQL injection in webhook-triggered automations, allows data exfiltration. CVE-2026-72849 is a cross-site request forgery (CSRF) vulnerability in the chat-link handoff endpoint, enabling account hijacking. CVE-2026-73304 involves the leakage of OAuth refresh tokens via user metadata endpoints. CVE-2026-73303 allows an authenticated attacker to initiate an email change for another user. CVE-2026-73306 bypasses account lockout mechanisms for non-existent users. CVE-2026-73301 allows basic users to enumerate tenant groups and user memberships. CVE-2026-73308 leaks sensitive user OAuth data during automation test results. CVE-2026-73307 allows builders to cause arbitrary file writes via the AI table-generation feature.

The majority of these vulnerabilities were patched in Budibase versions prior to 3.40.0 or 3.40.1. Users are strongly advised to update to the latest available versions to mitigate these risks. The sheer volume and diversity of these vulnerabilities, disclosed over a two-day period, indicate a widespread security concern within the affected Budibase versions.

The batch of 24 vulnerabilities disclosed between August 12-14, 2026, affects multiple versions of Budibase prior to 3.40.0 and 3.40.1. Critical vulnerabilities include SQL injection in webhook automations (CVE-2026-72851), S3 object key traversal (CVE-2026-72850), and OIDC flow bypass (CVE-2026-73302). High severity flaws encompass SQL injection in MySQL and Oracle connectors (CVE-2026-73300, CVE-2026-72853), NoSQL injection in MongoDB (CVE-2026-73618, CVE-2026-73617), SSRF in automations and query execution (CVE-2026-35219, CVE-2026-72855), and authorization bypasses (CVE-2026-72856, CVE-2026-73305). Sensitive data exposure includes datasource credentials (CVE-2026-72857) and OAuth tokens (CVE-2026-73304). Patches for these vulnerabilities are available in Budibase versions 3.40.0 and 3.40.1. The coordinated disclosure of 24 vulnerabilities highlights a critical need for immediate updates for Budibase users. The broad range of issues, from injection flaws to SSRF and auth bypasses, indicates systemic security weaknesses in older versions. CVE-2026-35219, CVE-2026-72859, CVE-2026-73408, CVE-2026-73305, CVE-2026-73304, CVE-2026-73302, CVE-2026-72857, CVE-2026-72856, CVE-2026-72855, CVE-2026-72853, CVE-2026-72851, CVE-2026-72850, CVE-2026-72849, CVE-2026-73618, CVE-2026-73617, CVE-2026-73409, CVE-2026-73407, CVE-2026-73406, CVE-2026-73308, CVE-2026-73307, CVE-2026-73306, CVE-2026-73303, CVE-2026-73301, CVE-2026-73300.

AI-written article. Grounded in 24 CVE records listed below.