A vulnerability was found in Budibase up to 3.39.x . It has been declared as critical . This vulnerability affects unknown code of the component Webhook Trigger Endpoint . Executing a manipulation can lead to sql injection. This vulnerability is registered as CVE-2026-72851 . It is possible to launch the attack remotely. No exploit is available. It is recommended to upgrade the affected component.