CVE-2026-72853

HIGH CVSS 4.0: 8.8 EPSS 0.24%
Updated Aug 14, 2026
Oracle
Parameter Value
CVSS 8.8 (HIGH)
Affected Versions before 3.40.0
Type CWE-89 (SQL Injection)
Vendor Oracle
Public PoC No

Budibase before 3.40.0 contains a SQL injection vulnerability in the Oracle datasource connector's post-write row lookup that fails to escape table names in identifiers. Attackers with write permission on a table with a double-quote in its name can inject SQL that executes as the datasource's database user to read or modify arbitrary data.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
High
Difficult to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
High
Admin privileges needed
User Interaction
Passive
Minimal interaction

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v4.0

Weakness Type (CWE)