Impact
Budibase prior to version 3.40.0 includes a flaw in webhook‑triggered automations that perform EXECUTE_QUERY steps. Attackers can POST specially crafted JSON payloads to the webhook trigger endpoint without authentication, causing the application to execute arbitrary SQL using the database credentials configured by the builder. This allows attackers to read sensitive data, alter records, and persist changes in connected data sources such as Snowflake, thereby compromising confidentiality and integrity of the data.
Affected Systems
Budibase Server releases earlier than version 3.40.0 are affected; all users running the product before this release are susceptible.
Risk and Exploitability
The flaw carries a CVSS score of 9, indicating a high severity level. No EPSS score is currently available and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Because the webhook endpoint is unauthenticated, exploitation can occur over the network from any host that can reach the endpoint, making it a remote attack vector with significant risk if unmitigated.
OpenCVE Enrichment