---
id: CVE-2026-73618
title: >-
  Budibase Server before 3.40.0 contains a NoSQL injection vulnerability in the
  MongoDB query execution endpoint where user-supplied parameters are
  interpolated into JSON query templates without proper sanitization of JSON
  metacharacters
summary: >-
  Budibase Server before 3.40.0 contains a NoSQL injection vulnerability in the
  MongoDB query execution endpoint where user-supplied parameters are
  interpolated into JSON query templates without proper sanitization of JSON
  metacharacters. …
severity: high
cvss: 8.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'
cwe:
  - CWE-943
vendor: budibase
product: server
affected:
  - server < 3.40.0
published: '2026-08-13'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:37.787'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73618'
references:
  - url: >-
      https://github.com/Budibase/budibase/security/advisories/GHSA-qw6m-8fw2-2v64
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/budibase-server-before-nosql-injection-via-json-parameter
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Budibase/budibase/security/advisories/GHSA-qw6m-8fw2-2v64
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-08-13T12:54:44.916968Z'
epss: 0.00505
epssPercentile: 0.41208
ingestedAt: '2026-10-08T16:52:14.715Z'
---

## Overview

Budibase Server before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB query execution endpoint where user-supplied parameters are interpolated into JSON query templates without proper sanitization of JSON metacharacters. Attackers with query write permission can inject JSON structural characters to alter MongoDB queries, bypassing filters to read, modify, or delete arbitrary documents.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
