CVE-2026-73618: Budibase Server before 3.40.0 NoSQL Injection via JSON Parameter
Budibase Server before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB query execution endpoint where user-supplied parameters are interpolated into JSON query templates without proper sanitization of JSON metacharacters. Attackers with query write permission can inject JSON structural characters to alter MongoDB queries, bypassing filters to read, modify, or delete arbitrary documents.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73618?
The severity of CVE-2026-73618 is rated high with a score of 8.3.
How do I fix CVE-2026-73618?
To fix CVE-2026-73618, upgrade Budibase Server to version 3.40.0 or later.
What type of vulnerability is CVE-2026-73618?
CVE-2026-73618 is a NoSQL injection vulnerability affecting the Budibase Server.
Who is affected by CVE-2026-73618?
Any user running Budibase Server versions prior to 3.40.0 with query write permissions is potentially affected by CVE-2026-73618.
What can attackers do with CVE-2026-73618?
Attackers can exploit CVE-2026-73618 to inject malicious JSON structures into MongoDB queries.