CVE-2026-73300Disclosure

LOWCVSS 9.6 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: true, enabling execution of multiple SQL statements in a single query. Attackers can inject malicious SQL commands through user input fields, leading to complete database compromise. This vulnerability is fixed in 3.40.0.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-08-12); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-12: 2Mentions · 2026-08-14: 1PoC Mentioned / Linked · 2026-08-12: 1Exploit Tool / Code · 2026-08-12: 1Technical Details · 2026-08-12: 1Technical Details · 2026-08-14: 108-1208-14
Signal classification2 categories
Disclosure
266.7%
Exploit
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-122
Disclosure1Exploit1
2026-08-141
Disclosure1
Full discourse3 posts
  • Aretiq.AI@AretiqAI
    Exploit

    ARETIQ Daily Vulnerability Bulletin — August 12, 2026 🔴 CRITICAL: CVE-2026-26035 (fortinet/fortiweb) AAS 14.9 — PoC available 🔴 CRITICAL: CVE-2026-17218 (ibm/i) AAS 12.9 — exploit available 🔴 CRITICAL: CVE-2026-73299 (microsoft/prompty) AAS 12.8 — exploit available 🔴 CRITICAL: CVE-2026-73263 (prowler-cloud/prowler) AAS 12.7 — exploit available 🔴 CRITICAL: CVE-2026-73300 (budibase/budibase) AAS 12.7 — exploit available + 2 more CRITICAL 30 vulnerabilities — CRITICAL: 7, HIGH: 23 Full bulletin: https://aretiq.ai/bulletins/2026-08-12/

    Post summary

    The bulletin lists several critical CVEs with publicly available PoCs and exploits, but no patches or reported active exploitation.

    00094526
    232 followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🔐 🚨 Budibase Mass Disclosure — 7 CVEs, CVSS 10.0 PEAK CVE-2026-72851 (10.0): Unauthenticated SQL injection via webhook CVE-2026-73300 (9.6): MySQL SQL injection → https://threataft.com/articles/budibase-mass-disclosure-7-cves #cybersecurity #infosec #Budibase #LowCode #Webhook #SQLi #ThreatIntel

    Post summary

    The tweet announces a mass disclosure of seven Budibase CVEs with high CVSS scores and specific SQLi details, linking to an external article for further information but providing no PoC, exploit, patch, or evidence of active exploitation.

    0000050
    36 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-73300 SQL Injection in Budibase Low-Code Platform Allows Database Compromise https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-73300

    Post summary

    The result is a disclosure of a SQL Injection flaw in Budibase that can lead to database compromise, with no evidence yet of exploitation or mitigation steps.

    00000121
    4.1K followersView on X

Explore more