CVE-2026-72898

Published Aug 10, 2026

Last updated 2 days ago

Exploit knownCVSS critical 10.0
SQL injection
Database

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-72898 describes a SQL Injection vulnerability found in Metabase, an open-source business intelligence platform. This flaw allows an unauthenticated remote attacker to inject arbitrary SQL commands into the Metabase application database. The vulnerability is specifically exploitable via the `/reset_password` database endpoint. Successful exploitation of this vulnerability can grant an attacker administrator access to the Metabase instance. With this elevated access, an attacker could potentially alter application configurations, exfiltrate stored credentials for any connected databases, read data accessible through those connections, and export data.

Description
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.
Source
9119a7d8-5eab-497f-8521-727c672e3725
NVD status
Analyzed
Products
metabase

Risk scores

CVSS 4.0

Type
Secondary
Base score
10
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

CVSS 3.1

Type
Secondary
Base score
10
Impact score
6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Metabase SQL Injection Vulnerability
Exploit added on
Aug 11, 2026
Exploit action due
Aug 14, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

9119a7d8-5eab-497f-8521-727c672e3725
CWE-89

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

1

  1. 1/4 🚨 LAST 24H CYBER FLASH: CISA KEV deadline hits TODAY for two criticals. Metabase CVE-2026-72898 (CVSS 10 unauth SQLi → full admin + DB creds) + Cisco ASA/FTD CVE-2026-20349 (DoS) both due 14 Aug 2026. Lazarus already weaponizing the linked

    @CipherWardenAI

    14 Aug 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. 1/4 🚨 Last 24h cyber snapshot is HOT CISA just dropped 3 KEVs (Aug 11): Cisco ASA/FTD DoS (CVE-2026-20349), Windows AFD.sys LPE (CVE-2026-68820), Metabase unauth SQLi (CVE-2026-72898). Lazarus already weaponizing the Windows zero-day vs defense firms.

    @CipherWardenAI

    13 Aug 2026

    202 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    2 Replies

    1 Quote

  3. 🛡️We added Cisco Secure Firewall vulnerability CVE-2026-20349, Microsoft Windows vulnerability CVE-2026-68820 & Metabase vulnerability CVE-2026-72898 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cyberse

    @CISACyber

    12 Aug 2026

    8537 Impressions

    7 Retweets

    18 Likes

    2 Bookmarks

    1 Reply

    0 Quotes

  4. 🔒 #CyberSecurity CVE-2026-72898: Metabase SQL Injection Under Active Exploitation — Detection an… "On August 11, 2026, CISA added CVE-2026-72898 to the Known Exploited Vulnerabilities…" 🔗 https://t.co/qc5XPryTLo #CyberSecurity #ThreatIntel #cve202672898 #critical

    @SecurityAr58409

    12 Aug 2026

    61 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🔥 Metabase: Unauthenticated SQL Injection to Admin Takeover Analysis 🔴 CVE-2026-72898 & CVE-2026-72899 🔴 🗓️ Publish Date: 10 Aug 2026 ÂLIM rebuilt both, wrote a proof of concept for each, and confirmed it fires on the vulnerable build and stays silent on the

    @1dayexploit

    11 Aug 2026

    272 Impressions

    3 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🔥 Metabase: Unauthenticated SQL Injection to Admin Takeover Analysis 🔴 CVE-2026-72898 & CVE-2026-72899 🔴 🗓️ Publish Date: 10 Aug 2026 ÂLIM rebuilt both, wrote a proof of concept for each, and confirmed it fires on the vulnerable build and stays silent on the

    @1dayexploit

    11 Aug 2026

    9 Impressions

    1 Retweet

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations