Threats Tagged 'cve-2026-54350'
View all threats tagged with 'cve-2026-54350'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-54350'
Click on any threat for detailed analysis and mitigation recommendations
Server: Budibase has nonymous NoSQL operator injection via published-app query templates (CVE-2026-54350)CVE-2026-54350 0 Budibase server versions up to 3.39.0 contain a critical NoSQL operator injection vulnerability (CVE-2026-54350) in the handling of published-app query templates. This flaw allows unauthenticated users to bypass authentication and CSRF protections when queries are set to the PUBLIC role, enabling them to read or modify all documents in various NoSQL data sources such as MongoDB, CouchDB, Elasticsearch, DynamoDB-PartiQL, or REST JSON collections. The vulnerability arises from unsafe substitution of user input into JSON query bodies without proper escaping, combined with insufficient input validation and authorization checks. SQL datasources are not affected. A patch is available for this issue. Join the discussion | GCVE Database | 06/23/2026, 17:43:10 UTC Added: 08/12/2026, 20:13:21 UTC |
Showing 1 to 1 of 1 result