CVE-2026-73300

Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: true, enabling execution of multiple SQL statements in a single query. Attackers can inject malicious SQL commands through user input fields, leading to complete database compromise. This vulnerability is fixed in 3.40.0.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-12 18:18

Updated : 2026-09-08 20:56


NVD link : CVE-2026-73300

Mitre link : CVE-2026-73300

CVE.ORG link : CVE-2026-73300


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')