A vulnerability categorized as critical has been discovered in Budibase Server up to 3.39.x. This issue affects some unknown processing of the component MongoDB Query Execution Endpoint. Executing a manipulation can lead to improper neutralization of special elements in data query logic.
The identification of this vulnerability is CVE-2026-73618. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.