CVE-2026-72853
Severity CVSS v4.0:
HIGH
Type:
CWE-89
SQL Injection
Publication date:
13/08/2026
Last modified:
18/08/2026
Description
Budibase before 3.40.0 contains a SQL injection vulnerability in the Oracle datasource connector's post-write row lookup that fails to escape table names in identifiers. Attackers with write permission on a table with a double-quote in its name can inject SQL that executes as the datasource's database user to read or modify arbitrary data.
Impact
Base Score 4.0
8.80
Severity 4.0
HIGH
Base Score 3.x
7.60
Severity 3.x
HIGH



