Sploitus

CVE-2026-72898

5 known exploits for CVE-2026-72898

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

Affected products
Metabase
Metabase
< 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, 0.63.5, 1.58.24, 1.59.21, 1.60.17, 1.61.11, 1.62.9, 1.63.5
CVSS 4.0
10.0 CRITICAL
CVSS 3.1
10.0 CRITICAL
EPSS
10.4% (95th percentile)
Weakness
CWE-89
NVD status
Analyzed
Published
2026-08-10
CVE-2026-72898 at NVD
Authoritative description, scoring and affected products

5 known exploits for CVE-2026-72898

Proof-of-concept code and exploit modules indexed by Sploitus