CVE-2026-73300: Budibase: SQL Injection via `multipleStatements: true`
Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: true, enabling execution of multiple SQL statements in a single query. Attackers can inject malicious SQL commands through user input fields, leading to complete database compromise. This vulnerability is fixed in 3.40.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Budibase (MySQL integration)to a version that resolves this vulnerability.Fixed in 3.40.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73300?
The severity of CVE-2026-73300 is critical with a CVSS score of 9.6.
What type of vulnerability is CVE-2026-73300?
CVE-2026-73300 is an SQL Injection vulnerability associated with the Budibase low-code platform.
How do I fix CVE-2026-73300?
To fix CVE-2026-73300, upgrade Budibase to version 3.40.0 or later where the multipleStatements configuration is disabled.
What are the risks associated with CVE-2026-73300?
CVE-2026-73300 allows attackers to execute multiple malicious SQL commands through user input, potentially leading to data compromise.
Which software is affected by CVE-2026-73300?
Budibase versions prior to 3.40.0 are affected by CVE-2026-73300.