CVE-2026-72898
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.
- Affected products
- Metabase
- Metabase
- < 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, 0.63.5, 1.58.24, 1.59.21, 1.60.17, 1.61.11, 1.62.9, 1.63.5
- CVSS 4.0
- 10.0 CRITICAL
- CVSS 3.1
- 10.0 CRITICAL
- EPSS
- 10.4% (95th percentile)
- Weakness
- CWE-89
- NVD status
- Analyzed
- Published
- 2026-08-10
CVE-2026-72898 at NVD
5 known exploits for CVE-2026-72898
Proof-of-concept code and exploit modules indexed by Sploitus