CVE-2026-72898

Published Aug 10, 2026

Last updated a month ago

Exploit knownCVSS critical 10.0
Zero-day
SQL injection
Database

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-72898 describes a SQL Injection vulnerability found in Metabase, an open-source business intelligence platform. This flaw allows an unauthenticated remote attacker to inject arbitrary SQL commands into the Metabase application database. The vulnerability is specifically exploitable via the `/reset_password` database endpoint. Successful exploitation of this vulnerability can grant an attacker administrator access to the Metabase instance. With this elevated access, an attacker could potentially alter application configurations, exfiltrate stored credentials for any connected databases, read data accessible through those connections, and export data.

Description
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.
Source
9119a7d8-5eab-497f-8521-727c672e3725
NVD status
Analyzed
Products
metabase

Risk scores

CVSS 4.0

Type
Secondary
Base score
10
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

CVSS 3.1

Type
Secondary
Base score
10
Impact score
6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Metabase SQL Injection Vulnerability
Exploit added on
Aug 11, 2026
Exploit action due
Aug 14, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

9119a7d8-5eab-497f-8521-727c672e3725
CWE-89

Social media

Hype score
Not currently trending
  1. ShinyHunters (G1057, UNC6240) continues to target finance, healthcare, and transport. They focus on credential theft (T1589.001) and phishing (T1566) to acquire PII. Monitor for these TTPs, especially if you're seeing activity around CVE-2026-35273 or CVE-2026-72898.

    @BytesNora

    12 Sept 2026

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2026-72898: unauth SQLi in Metabase. Attackers got admin. Framework: names, emails, addresses stolen. CISA added the CVSS 10.0 bug to KEV. #cybersecurity #infosec #CISA #KEV #SaaS

    @Caldura7

    3 Sept 2026

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 WORKING PoC CLAIMED FOR METABASE SQL INJECTION — CVE-2026-72898 A threat actor on an underground cybercrime forum claims to have released working proof-of-concept code targeting CVE-2026-72898, described in the post as a SQL injection vulnerability affecting Metabase. htt

    @DailyDarkWeb

    30 Aug 2026

    6227 Impressions

    4 Retweets

    28 Likes

    7 Bookmarks

    1 Reply

    0 Quotes

  4. 🚨 🚨 CVE-2026-72898: Critical Metabase SQLi is being actively exploited. The unauthenticated flaw in the password-reset flow could let attackers compromise vulnerable instances and gain admin access. Patch ASAP! 🔥 #CyberSecurity #CVE https://t.co/eBxSEXdHJ9

    @RealBugthrive

    28 Aug 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2026-72898 (CVSS 10.0) https://t.co/y0xuduSLqe

    @_Charlie_Chang_

    28 Aug 2026

    103 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Israel’s largest regulated broker, Bits of Gold, suffered a major exploit on its Metabase analytics software (CVE-2026-72898). Hackers successfully exfiltrated the national ID numbers, bank details, and personal data of up to 250,000 users.

    @Cletaisme

    22 Aug 2026

    58 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: EGE-GH-z2Wb7PG ( CVE-2026-72898 ) EGE-GH-UkSJfvx ( CVE-2026-73678 ) EGE-GH-MKUk78n ( CVE-2023-22621 ) EGE-GH-EjpQM0Q ( CVE-2025-3243, CVE-2025-32433 ) EGE-GH-seDm3r2 ( CVE-2025-55182 ) ..🧵👇

    @exploitgrid

    17 Aug 2026

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  8. For defenders, metabase zero-day turns bi dashboards into a data-exposure path should move fast. Metabase CVE-2026-72898 is an actively exploited unauthenticated SQL injection flaw. Patch… 🔗 Details → https://t.co/iwq0O0XHkF

    @SocXAInvaders

    17 Aug 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. We are also scanning & reporting Metabase IPs likely unpatched to CVE-2026-72898 SQLi, which is exploited in the wild & on @CISACyber KEV. 2171 unpatched (version check) instances seen 2026-08-15. Top US (603), Germany (278) Dashboard World Map stats: https://t.co/NpnH

    @Shadowserver

    16 Aug 2026

    1627 Impressions

    5 Retweets

    6 Likes

    2 Bookmarks

    1 Reply

    0 Quotes

  10. Metabase zero-day (CVE-2026-72898) has been actively exploited in the wild, allowing unauthenticated admin access. Framework confirmed customer data exposure. Organizations running Metabase should patch immediately and audit for unusual activity. #CyberSecurity

    @Lumideezy

    16 Aug 2026

    93 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. 🔥 CyberForge CVE of the Day #025 🚨 CVE-2026-72898 — Metabase Unauthenticated SQL Injection to Admin Takeover Metabase has patched a maximum-severity SQL injection that was actively exploited as a zero-day. An unauthenticated remote attacker can target the public

    @lee1981b

    16 Aug 2026

    80 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. CVE-2026-72898: Metabase Setup Endpoint SQLi Patch by UBITQUITY. This repository contains the hotfix for CVE-2026-72898, an unauthenticated SQL Injection vulnerability in the setup endpoint of self-hosted Metabase instances. Left unpatched, attackers can bypass the setup token

    @ubitquity_io

    15 Aug 2026

    190 Impressions

    3 Retweets

    4 Likes

    0 Bookmarks

    0 Replies

    1 Quote

  13. Trezorデータ漏洩:Metabaseのゼロデイ脆弱性CVE-2026-72898により顧客13,689人分の情報が流出 https://t.co/gisP3ZLoI5

    @TYOBlackHatNews

    15 Aug 2026

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. 🚨 CISA KEV ZERO-DAY ADDITION 🚨 CISA confirms active exploitation of Metabase SQL injection (CVE-2026-72898). ⚠️ Web3 threat: Direct extraction of production database connections, API secrets, and wallet address mapping tables. Full report 👇 https://t.co/Jl4MHVd4I

    @AdvancedHacker

    15 Aug 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 1/4 🚨 LAST 24H CYBER FLASH: CISA KEV deadline hits TODAY for two criticals. Metabase CVE-2026-72898 (CVSS 10 unauth SQLi → full admin + DB creds) + Cisco ASA/FTD CVE-2026-20349 (DoS) both due 14 Aug 2026. Lazarus already weaponizing the linked

    @CipherWardenAI

    14 Aug 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  16. 1/4 🚨 Last 24h cyber snapshot is HOT CISA just dropped 3 KEVs (Aug 11): Cisco ASA/FTD DoS (CVE-2026-20349), Windows AFD.sys LPE (CVE-2026-68820), Metabase unauth SQLi (CVE-2026-72898). Lazarus already weaponizing the Windows zero-day vs defense firms.

    @CipherWardenAI

    13 Aug 2026

    202 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    2 Replies

    1 Quote

  17. 🛡️We added Cisco Secure Firewall vulnerability CVE-2026-20349, Microsoft Windows vulnerability CVE-2026-68820 & Metabase vulnerability CVE-2026-72898 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cyberse

    @CISACyber

    12 Aug 2026

    8537 Impressions

    7 Retweets

    18 Likes

    2 Bookmarks

    1 Reply

    0 Quotes

  18. 🔒 #CyberSecurity CVE-2026-72898: Metabase SQL Injection Under Active Exploitation — Detection an… "On August 11, 2026, CISA added CVE-2026-72898 to the Known Exploited Vulnerabilities…" 🔗 https://t.co/qc5XPryTLo #CyberSecurity #ThreatIntel #cve202672898 #critical

    @SecurityAr58409

    12 Aug 2026

    61 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. 🔥 Metabase: Unauthenticated SQL Injection to Admin Takeover Analysis 🔴 CVE-2026-72898 & CVE-2026-72899 🔴 🗓️ Publish Date: 10 Aug 2026 ÂLIM rebuilt both, wrote a proof of concept for each, and confirmed it fires on the vulnerable build and stays silent on the

    @1dayexploit

    11 Aug 2026

    272 Impressions

    3 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. 🔥 Metabase: Unauthenticated SQL Injection to Admin Takeover Analysis 🔴 CVE-2026-72898 & CVE-2026-72899 🔴 🗓️ Publish Date: 10 Aug 2026 ÂLIM rebuilt both, wrote a proof of concept for each, and confirmed it fires on the vulnerable build and stays silent on the

    @1dayexploit

    11 Aug 2026

    9 Impressions

    1 Retweet

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations