Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-72898: Metabase: Unauthenticated SQL Injection via Reset Password
CVE-2026-72898 · published 24 days ago · actively exploited
Summary
Metabase's reset password feature can be exploited by an attacker to inject malicious SQL code, potentially gaining administrator access to the connected database. This vulnerability allows an attacker to access sensitive data and make unauthorized changes. To protect your instance, update Metabase to the latest version and ensure you have strong passwords in place.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| metabase | metabase |
< x.58.24 >= 0.58.0, < 0.58.24 >= 0.59.0, < 0.59.21 >= 0.60.0, < 0.60.17 >= 0.61.0, < 0.61.11 >= 0.62.0, < 0.62.9 >= 0.63.0, < 0.63.5 >= 1.58.0, < 1.58.24 >= 1.59.0, < 1.59.21 >= 1.60.0, < 1.60.17 >= 1.61.0, < 1.61.11 >= 1.62.0, < 1.62.9 1 more version range
|
Original advisory text
Metabase SQL Injection Vulnerability
Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.
References
- https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/...
- https://www.cve.org/CVERecord?id=CVE-2026-72898
- https://www.metabase.com/blog/security-update
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-...
Severity
10.0
Critical
CVSS 3.1: 10.0 (NVD)
CVSS 4.0: 10.0 (NVD)
Exploitation
Known exploited
Listed in the CISA KEV catalogue - exploitation confirmed in the wild.
EPSS 82%
Type
CWE-89SQL Injection
Timeline
Published10 Aug 2026
Updated31 Aug 2026
First seen10 Aug 2026
Monitor software like this
Free during beta