CVE-2026-72898
Published Aug 10, 2026
Last updated a month ago
AI description
CVE-2026-72898 describes a SQL Injection vulnerability found in Metabase, an open-source business intelligence platform. This flaw allows an unauthenticated remote attacker to inject arbitrary SQL commands into the Metabase application database. The vulnerability is specifically exploitable via the `/reset_password` database endpoint. Successful exploitation of this vulnerability can grant an attacker administrator access to the Metabase instance. With this elevated access, an attacker could potentially alter application configurations, exfiltrate stored credentials for any connected databases, read data accessible through those connections, and export data.
- Description
- Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.
- Source
- 9119a7d8-5eab-497f-8521-727c672e3725
- NVD status
- Analyzed
- Products
- metabase
CVSS 4.0
- Type
- Secondary
- Base score
- 10
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
CVSS 3.1
- Type
- Secondary
- Base score
- 10
- Impact score
- 6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- Metabase SQL Injection Vulnerability
- Exploit added on
- Aug 11, 2026
- Exploit action due
- Aug 14, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- 9119a7d8-5eab-497f-8521-727c672e3725
- CWE-89
- Hype score
- Not currently trending
ShinyHunters (G1057, UNC6240) continues to target finance, healthcare, and transport. They focus on credential theft (T1589.001) and phishing (T1566) to acquire PII. Monitor for these TTPs, especially if you're seeing activity around CVE-2026-35273 or CVE-2026-72898.
@BytesNora
12 Sept 2026
8 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-72898: unauth SQLi in Metabase. Attackers got admin. Framework: names, emails, addresses stolen. CISA added the CVSS 10.0 bug to KEV. #cybersecurity #infosec #CISA #KEV #SaaS
@Caldura7
3 Sept 2026
28 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 WORKING PoC CLAIMED FOR METABASE SQL INJECTION — CVE-2026-72898 A threat actor on an underground cybercrime forum claims to have released working proof-of-concept code targeting CVE-2026-72898, described in the post as a SQL injection vulnerability affecting Metabase. htt
@DailyDarkWeb
30 Aug 2026
6227 Impressions
4 Retweets
28 Likes
7 Bookmarks
1 Reply
0 Quotes
🚨 🚨 CVE-2026-72898: Critical Metabase SQLi is being actively exploited. The unauthenticated flaw in the password-reset flow could let attackers compromise vulnerable instances and gain admin access. Patch ASAP! 🔥 #CyberSecurity #CVE https://t.co/eBxSEXdHJ9
@RealBugthrive
28 Aug 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-72898 (CVSS 10.0) https://t.co/y0xuduSLqe
@_Charlie_Chang_
28 Aug 2026
103 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Israel’s largest regulated broker, Bits of Gold, suffered a major exploit on its Metabase analytics software (CVE-2026-72898). Hackers successfully exfiltrated the national ID numbers, bank details, and personal data of up to 250,000 users.
@Cletaisme
22 Aug 2026
58 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: EGE-GH-z2Wb7PG ( CVE-2026-72898 ) EGE-GH-UkSJfvx ( CVE-2026-73678 ) EGE-GH-MKUk78n ( CVE-2023-22621 ) EGE-GH-EjpQM0Q ( CVE-2025-3243, CVE-2025-32433 ) EGE-GH-seDm3r2 ( CVE-2025-55182 ) ..🧵👇
@exploitgrid
17 Aug 2026
29 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
For defenders, metabase zero-day turns bi dashboards into a data-exposure path should move fast. Metabase CVE-2026-72898 is an actively exploited unauthenticated SQL injection flaw. Patch… 🔗 Details → https://t.co/iwq0O0XHkF
@SocXAInvaders
17 Aug 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
We are also scanning & reporting Metabase IPs likely unpatched to CVE-2026-72898 SQLi, which is exploited in the wild & on @CISACyber KEV. 2171 unpatched (version check) instances seen 2026-08-15. Top US (603), Germany (278) Dashboard World Map stats: https://t.co/NpnH
@Shadowserver
16 Aug 2026
1627 Impressions
5 Retweets
6 Likes
2 Bookmarks
1 Reply
0 Quotes
Metabase zero-day (CVE-2026-72898) has been actively exploited in the wild, allowing unauthenticated admin access. Framework confirmed customer data exposure. Organizations running Metabase should patch immediately and audit for unusual activity. #CyberSecurity
@Lumideezy
16 Aug 2026
93 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔥 CyberForge CVE of the Day #025 🚨 CVE-2026-72898 — Metabase Unauthenticated SQL Injection to Admin Takeover Metabase has patched a maximum-severity SQL injection that was actively exploited as a zero-day. An unauthenticated remote attacker can target the public
@lee1981b
16 Aug 2026
80 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-72898: Metabase Setup Endpoint SQLi Patch by UBITQUITY. This repository contains the hotfix for CVE-2026-72898, an unauthenticated SQL Injection vulnerability in the setup endpoint of self-hosted Metabase instances. Left unpatched, attackers can bypass the setup token
@ubitquity_io
15 Aug 2026
190 Impressions
3 Retweets
4 Likes
0 Bookmarks
0 Replies
1 Quote
Trezorデータ漏洩:Metabaseのゼロデイ脆弱性CVE-2026-72898により顧客13,689人分の情報が流出 https://t.co/gisP3ZLoI5
@TYOBlackHatNews
15 Aug 2026
28 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CISA KEV ZERO-DAY ADDITION 🚨 CISA confirms active exploitation of Metabase SQL injection (CVE-2026-72898). ⚠️ Web3 threat: Direct extraction of production database connections, API secrets, and wallet address mapping tables. Full report 👇 https://t.co/Jl4MHVd4I
@AdvancedHacker
15 Aug 2026
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
1/4 🚨 LAST 24H CYBER FLASH: CISA KEV deadline hits TODAY for two criticals. Metabase CVE-2026-72898 (CVSS 10 unauth SQLi → full admin + DB creds) + Cisco ASA/FTD CVE-2026-20349 (DoS) both due 14 Aug 2026. Lazarus already weaponizing the linked
@CipherWardenAI
14 Aug 2026
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
1/4 🚨 Last 24h cyber snapshot is HOT CISA just dropped 3 KEVs (Aug 11): Cisco ASA/FTD DoS (CVE-2026-20349), Windows AFD.sys LPE (CVE-2026-68820), Metabase unauth SQLi (CVE-2026-72898). Lazarus already weaponizing the Windows zero-day vs defense firms.
@CipherWardenAI
13 Aug 2026
202 Impressions
1 Retweet
0 Likes
0 Bookmarks
2 Replies
1 Quote
🛡️We added Cisco Secure Firewall vulnerability CVE-2026-20349, Microsoft Windows vulnerability CVE-2026-68820 & Metabase vulnerability CVE-2026-72898 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cyberse
@CISACyber
12 Aug 2026
8537 Impressions
7 Retweets
18 Likes
2 Bookmarks
1 Reply
0 Quotes
🔒 #CyberSecurity CVE-2026-72898: Metabase SQL Injection Under Active Exploitation — Detection an… "On August 11, 2026, CISA added CVE-2026-72898 to the Known Exploited Vulnerabilities…" 🔗 https://t.co/qc5XPryTLo #CyberSecurity #ThreatIntel #cve202672898 #critical
@SecurityAr58409
12 Aug 2026
61 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔥 Metabase: Unauthenticated SQL Injection to Admin Takeover Analysis 🔴 CVE-2026-72898 & CVE-2026-72899 🔴 🗓️ Publish Date: 10 Aug 2026 ÂLIM rebuilt both, wrote a proof of concept for each, and confirmed it fires on the vulnerable build and stays silent on the
@1dayexploit
11 Aug 2026
272 Impressions
3 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
🔥 Metabase: Unauthenticated SQL Injection to Admin Takeover Analysis 🔴 CVE-2026-72898 & CVE-2026-72899 🔴 🗓️ Publish Date: 10 Aug 2026 ÂLIM rebuilt both, wrote a proof of concept for each, and confirmed it fires on the vulnerable build and stays silent on the
@1dayexploit
11 Aug 2026
9 Impressions
1 Retweet
3 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:metabase:metabase:*:*:*:*:-:*:*:*",
"matchCriteriaId": "F8213D45-9A31-4B33-AEE2-46E1DC824799",
"versionEndExcluding": "0.58.24",
"versionStartIncluding": "0.58.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:metabase:metabase:*:*:*:*:-:*:*:*",
"matchCriteriaId": "3DA1C6EA-45C1-4F4A-8A94-9A85A4EAA659",
"versionEndExcluding": "0.59.21",
"versionStartIncluding": "0.59.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:metabase:metabase:*:*:*:*:-:*:*:*",
"matchCriteriaId": "2D06D9D9-092B-4191-8F53-01E0B8936373",
"versionEndExcluding": "0.60.17",
"versionStartIncluding": "0.60.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:metabase:metabase:*:*:*:*:-:*:*:*",
"matchCriteriaId": "58026B24-B825-41C5-A6AB-07DCFAC86BA8",
"versionEndExcluding": "0.61.11",
"versionStartIncluding": "0.61.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:metabase:metabase:*:*:*:*:-:*:*:*",
"matchCriteriaId": "58DB3F1E-C017-47DB-A9EC-BE2A7BCE7969",
"versionEndExcluding": "0.62.9",
"versionStartIncluding": "0.62.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:metabase:metabase:*:*:*:*:-:*:*:*",
"matchCriteriaId": "953341C6-9022-439D-BE3D-64925359F0DF",
"versionEndExcluding": "0.63.5",
"versionStartIncluding": "0.63.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:metabase:metabase:*:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "F43FE1BC-849E-4CC0-B2FC-C24F1EB9E74D",
"versionEndExcluding": "1.58.24",
"versionStartIncluding": "1.58.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:metabase:metabase:*:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "5697F23D-749D-4CEA-8024-721B914AC28F",
"versionEndExcluding": "1.59.21",
"versionStartIncluding": "1.59.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:metabase:metabase:*:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "E8383356-C138-41BB-9B50-0A31FE1FAB04",
"versionEndExcluding": "1.60.17",
"versionStartIncluding": "1.60.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:metabase:metabase:*:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "02DCC833-E08F-400E-B1F3-D6C5E370F979",
"versionEndExcluding": "1.61.11",
"versionStartIncluding": "1.61.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:metabase:metabase:*:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "15C32BDC-72A1-4C32-B1DB-C57DDB1F3D37",
"versionEndExcluding": "1.62.9",
"versionStartIncluding": "1.62.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:metabase:metabase:*:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "7B79BC41-8595-4A5A-8AD2-19BCEFE9348E",
"versionEndExcluding": "1.63.5",
"versionStartIncluding": "1.63.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]