CVE-2026-72898
Published Aug 10, 2026
Last updated 2 days ago
AI description
CVE-2026-72898 describes a SQL Injection vulnerability found in Metabase, an open-source business intelligence platform. This flaw allows an unauthenticated remote attacker to inject arbitrary SQL commands into the Metabase application database. The vulnerability is specifically exploitable via the `/reset_password` database endpoint. Successful exploitation of this vulnerability can grant an attacker administrator access to the Metabase instance. With this elevated access, an attacker could potentially alter application configurations, exfiltrate stored credentials for any connected databases, read data accessible through those connections, and export data.
- Description
- Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.
- Source
- 9119a7d8-5eab-497f-8521-727c672e3725
- NVD status
- Analyzed
- Products
- metabase
CVSS 4.0
- Type
- Secondary
- Base score
- 10
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
CVSS 3.1
- Type
- Secondary
- Base score
- 10
- Impact score
- 6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- Metabase SQL Injection Vulnerability
- Exploit added on
- Aug 11, 2026
- Exploit action due
- Aug 14, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- 9119a7d8-5eab-497f-8521-727c672e3725
- CWE-89
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
1
1/4 🚨 LAST 24H CYBER FLASH: CISA KEV deadline hits TODAY for two criticals. Metabase CVE-2026-72898 (CVSS 10 unauth SQLi → full admin + DB creds) + Cisco ASA/FTD CVE-2026-20349 (DoS) both due 14 Aug 2026. Lazarus already weaponizing the linked
@CipherWardenAI
14 Aug 2026
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
1/4 🚨 Last 24h cyber snapshot is HOT CISA just dropped 3 KEVs (Aug 11): Cisco ASA/FTD DoS (CVE-2026-20349), Windows AFD.sys LPE (CVE-2026-68820), Metabase unauth SQLi (CVE-2026-72898). Lazarus already weaponizing the Windows zero-day vs defense firms.
@CipherWardenAI
13 Aug 2026
202 Impressions
1 Retweet
0 Likes
0 Bookmarks
2 Replies
1 Quote
🛡️We added Cisco Secure Firewall vulnerability CVE-2026-20349, Microsoft Windows vulnerability CVE-2026-68820 & Metabase vulnerability CVE-2026-72898 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cyberse
@CISACyber
12 Aug 2026
8537 Impressions
7 Retweets
18 Likes
2 Bookmarks
1 Reply
0 Quotes
🔒 #CyberSecurity CVE-2026-72898: Metabase SQL Injection Under Active Exploitation — Detection an… "On August 11, 2026, CISA added CVE-2026-72898 to the Known Exploited Vulnerabilities…" 🔗 https://t.co/qc5XPryTLo #CyberSecurity #ThreatIntel #cve202672898 #critical
@SecurityAr58409
12 Aug 2026
61 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔥 Metabase: Unauthenticated SQL Injection to Admin Takeover Analysis 🔴 CVE-2026-72898 & CVE-2026-72899 🔴 🗓️ Publish Date: 10 Aug 2026 ÂLIM rebuilt both, wrote a proof of concept for each, and confirmed it fires on the vulnerable build and stays silent on the
@1dayexploit
11 Aug 2026
272 Impressions
3 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
🔥 Metabase: Unauthenticated SQL Injection to Admin Takeover Analysis 🔴 CVE-2026-72898 & CVE-2026-72899 🔴 🗓️ Publish Date: 10 Aug 2026 ÂLIM rebuilt both, wrote a proof of concept for each, and confirmed it fires on the vulnerable build and stays silent on the
@1dayexploit
11 Aug 2026
9 Impressions
1 Retweet
3 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:metabase:metabase:*:*:*:*:-:*:*:*",
"matchCriteriaId": "F8213D45-9A31-4B33-AEE2-46E1DC824799",
"versionEndExcluding": "0.58.24",
"versionStartIncluding": "0.58.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:metabase:metabase:*:*:*:*:-:*:*:*",
"matchCriteriaId": "3DA1C6EA-45C1-4F4A-8A94-9A85A4EAA659",
"versionEndExcluding": "0.59.21",
"versionStartIncluding": "0.59.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:metabase:metabase:*:*:*:*:-:*:*:*",
"matchCriteriaId": "2D06D9D9-092B-4191-8F53-01E0B8936373",
"versionEndExcluding": "0.60.17",
"versionStartIncluding": "0.60.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:metabase:metabase:*:*:*:*:-:*:*:*",
"matchCriteriaId": "58026B24-B825-41C5-A6AB-07DCFAC86BA8",
"versionEndExcluding": "0.61.11",
"versionStartIncluding": "0.61.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:metabase:metabase:*:*:*:*:-:*:*:*",
"matchCriteriaId": "58DB3F1E-C017-47DB-A9EC-BE2A7BCE7969",
"versionEndExcluding": "0.62.9",
"versionStartIncluding": "0.62.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:metabase:metabase:*:*:*:*:-:*:*:*",
"matchCriteriaId": "953341C6-9022-439D-BE3D-64925359F0DF",
"versionEndExcluding": "0.63.5",
"versionStartIncluding": "0.63.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:metabase:metabase:*:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "F43FE1BC-849E-4CC0-B2FC-C24F1EB9E74D",
"versionEndExcluding": "1.58.24",
"versionStartIncluding": "1.58.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:metabase:metabase:*:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "5697F23D-749D-4CEA-8024-721B914AC28F",
"versionEndExcluding": "1.59.21",
"versionStartIncluding": "1.59.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:metabase:metabase:*:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "E8383356-C138-41BB-9B50-0A31FE1FAB04",
"versionEndExcluding": "1.60.17",
"versionStartIncluding": "1.60.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:metabase:metabase:*:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "02DCC833-E08F-400E-B1F3-D6C5E370F979",
"versionEndExcluding": "1.61.11",
"versionStartIncluding": "1.61.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:metabase:metabase:*:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "15C32BDC-72A1-4C32-B1DB-C57DDB1F3D37",
"versionEndExcluding": "1.62.9",
"versionStartIncluding": "1.62.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:metabase:metabase:*:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "7B79BC41-8595-4A5A-8AD2-19BCEFE9348E",
"versionEndExcluding": "1.63.5",
"versionStartIncluding": "1.63.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]