CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-73618

highCVSS 8.3covered by 1 sourcefirst seen 2026-08-13
Budibase Server before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB query execution endpoint where user-supplied parameters are interpolated into JSON query templates without proper sanitization of JSON metacharacters. Attackers with query write permission can inject JSON structural characters to alter MongoDB queries, bypassing filters to read, modify, or delete arbitrary documents.

⚡ Watch CVE-2026-73618

Get an email if CVE-2026-73618 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-73618

CVE.org record

Embed the live status

CVE-2026-73618 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-73618 status](https://www.csirts.com/badge/CVE-2026-73618)](https://www.csirts.com/cve/CVE-2026-73618)