CVE-2026-73617: Improper Neutralization of Special Elements in Data Query Logic in budibase server
Budibase server versions before 3.40.0 have a NoSQL injection vulnerability in the MongoDB datasource integration. This occurs because user-supplied parameters are processed with handlebars using noEscaping: true and without filtering MongoDB operators. Exploitation can allow attackers to bypass per-user access controls, read arbitrary documents, execute JavaScript via $where operators, or modify collections through update and delete operations.
AI Analysis
Technical Summary
CVE-2026-73617 is a NoSQL injection vulnerability affecting Budibase server prior to version 3.40.0. The vulnerability arises from the use of handlebars template processing with noEscaping: true on user-supplied parameters combined with a lack of operator filtering in MongoDB queries. This allows attackers to inject MongoDB operators through query parameters, enabling unauthorized access to data, execution of arbitrary JavaScript code via the $where operator, and modification of database collections through update and delete operations.
Potential Impact
An attacker with at least low privileges can exploit this vulnerability to bypass per-user access controls, read arbitrary documents from the database, execute arbitrary JavaScript code on the database server, and perform unauthorized update or delete operations on collections. This can lead to data disclosure, data tampering, and potential compromise of the database integrity.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid using vulnerable versions prior to 3.40.0 or implement strict input validation and operator filtering on MongoDB queries to prevent injection. Monitor vendor channels for updates and apply patches once released.
CVE-2026-73617: Improper Neutralization of Special Elements in Data Query Logic in budibase server
Description
Budibase server versions before 3.40.0 have a NoSQL injection vulnerability in the MongoDB datasource integration. This occurs because user-supplied parameters are processed with handlebars using noEscaping: true and without filtering MongoDB operators. Exploitation can allow attackers to bypass per-user access controls, read arbitrary documents, execute JavaScript via $where operators, or modify collections through update and delete operations.
CVSS v4.0
Score 7.1high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-73617 is a NoSQL injection vulnerability affecting Budibase server prior to version 3.40.0. The vulnerability arises from the use of handlebars template processing with noEscaping: true on user-supplied parameters combined with a lack of operator filtering in MongoDB queries. This allows attackers to inject MongoDB operators through query parameters, enabling unauthorized access to data, execution of arbitrary JavaScript code via the $where operator, and modification of database collections through update and delete operations.
Potential Impact
An attacker with at least low privileges can exploit this vulnerability to bypass per-user access controls, read arbitrary documents from the database, execute arbitrary JavaScript code on the database server, and perform unauthorized update or delete operations on collections. This can lead to data disclosure, data tampering, and potential compromise of the database integrity.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid using vulnerable versions prior to 3.40.0 or implement strict input validation and operator filtering on MongoDB queries to prevent injection. Monitor vendor channels for updates and apply patches once released.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-13T11:16:27.835Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7dbdfbbf8831d5393225e1
Added to database: 08/13/2026, 12:52:11 UTC
Last enriched: 08/13/2026, 12:55:52 UTC
Last updated: 08/13/2026, 13:01:24 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.