OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100683

HIGH · CVSS 8 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Budibase versions prior to 3.45.0 are vulnerable due to improper handling of SQL identifiers in column rename operations, allowing attackers with DDL rights on MySQL or MSSQL databases to inject arbitrary SQL commands. This vulnerability can lead to unauthorized database access and manipulation, bypassing Budibase's permission controls. Organizations using Budibase should prioritize upgrading to version 3.45.0 to mitigate the risk of potential data breaches or destructive actions on their databases.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100683
Severity
HIGH
CVSS
8
EPSS
0.21%

Original NVD Description

Budibase (@budibase/server) before 3.45.0 builds MySQL and MSSQL column-rename DDL in packages/backend-core/src/sql/sqlTable.ts by interpolating identifiers directly into a raw query string (backtick-quoted for MySQL, a single-quoted sp_rename literal for MSSQL) without applying the project's quoteMySqlIdentifier / quoteSqlServerIdentifier helpers. An attacker with DDL rights on a connected MySQL/MSSQL datasource can create a column whose name contains a backtick (MySQL) or single quote (MSSQL) plus additional SQL; Budibase's schema introspection stores the name verbatim, and when a Budibase builder later renames that column through the UI (POST /api/tables with _rename.old), the embedded quote character terminates the identifier and the injected SQL is executed. Because the MySQL connection is opened with multipleStatements: true, stacked statements run as Budibase's datasource user, allowing arbitrary reads, writes, or destructive operations on the connected database outside Budibase's row/table permission model. Fixed in 3.45.0.