← Back to Research Blog
CRITICAL CVE-2026-72851

Critical Unauthenticated SQL Injection in Budibase Allows Snowflake Compromise

10.0
CRITICAL
budibase, snowflake
2026-08-18

Overview

CVE-2026-72851 is a CVSS 10.0 SQL injection vulnerability in Budibase versions before 3.40.0 that enables unauthenticated attackers to execute arbitrary SQL commands on connected databases like Snowflake through crafted webhook requests. Exploitation can bypass authentication and leverage builder credentials to exfiltrate, modify, or persist in enterprise data systems.


Technical Analysis

Budibase's webhook endpoints with EXECUTE_QUERY steps fail to sanitize input in payloads, allowing attackers to inject malicious SQL code. Attackers can POST malicious JSON to /api/webhooks/trigger/<webhook-id> endpoints, executing queries with builder-privileged database credentials. This vulnerability is trivially exploitable via standard HTTP requests without authentication, targeting widely-used databases including Snowflake to achieve persistence or data theft.

Enterprise & DIB Impact

Defense Industrial Base (DIB) organizations relying on Budibase integrations with Snowflake or other database platforms are at critical risk of credential theft, sensitive data exposure, and compliance violations. State-sponsored or cybercriminal actors could exploit this flaw to infiltrate secure enterprise data lakes, industrial control systems, or classified research repositories.

Recommended Actions

Need Help Assessing Your Exposure?

Axiom Cyber Research provides vulnerability assessment, red team operations, and security advisory services to the Defense Industrial Base and regulated sectors.

Schedule a Consultation
Full security advisory on 247alerts.net →
Axiom Cyber Research
Axiom Cyber Research, LLC is a Service-Disabled Veteran-Owned Small Business (SDVOSB) providing elite cybersecurity consulting to the Defense Industrial Base and regulated sectors. Founded by a 20+ year veteran with deep offensive and defensive cyber expertise. Our CVE intelligence program actively tracks emerging vulnerabilities to help organizations prioritize remediation and reduce exposure windows.
Baltimore, MD  ·  axiomcyber.io  ·  247alerts.net  ·  SDVOSB  ·  NAICS 541512