A vulnerability was found in Budibase up to 3.39.17 . It has been classified as problematic . Impacted is an unknown function of the file packages/server/src/integrations/mysql.ts of the component MySQL Integration . The manipulation of the argument tableName leads to sql injection. This vulnerability is listed as CVE-2026-73408 . The attack may be initiated remotely. There is no available exploit. Upgrading the affected component is recommended.