## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-0XBLACKASH-CVE-2026-72898
# π΄ CVE-2026-72898 - `Unauthenticated SQL Injection`

### Metabase β Unauthenticated SQL Injection β Full Administrator Takeover
    
* * *
## π Overview
**CVE-2026-72898** is a **maximum-severity (CVSS 10.0)** unauthenticated SQL injection vulnerability in Metabase that allows a remote attacker to inject arbitrary SQL into the application database via the password-reset endpoint.
Successful exploitation grants **full administrator access** to the Metabase instance. From there, an attacker can:
* Modify application configuration
* Steal stored credentials for connected databases
* Read any data accessible through those connections
* Export sensitive data at will
> **This vulnerability was exploited in the wild as a zero-day** against Metabase Cloud and multiple self-hosted customers.
* * *
## β‘ Key Details
Field| Value
---|---
**CVE ID**| CVE-2026-72898
**GHSA**| GHSA-vwf4-m7j8-wcjf
**Severity**| Critical
**CVSS v3.1**| `10.0` β `AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H`
**CVSS v4.0**| `10.0`
**CWE**| CWE-89 β Improper Neutralization of Special Elements used in an SQL Command
**Attack Vector**| Network
**Authentication**| None required
**User Interaction**| None
**Exploitation Status**| **Actively exploited in the wild** (Zero-day)
**CISA KEV**| Listed
* * *
## π― Affected Endpoint
root@kitploit:~
POST /api/session/reset_password

An unauthenticated attacker can send a crafted request to this endpoint that results in arbitrary SQL execution against the Metabase application database.
* * *
## π¦ Affected Versions
Branch| Affected Versions| Fixed Version
---|---|---
**x.58**| β₯ x.58.0 and < x.58.24| **x.58.24**
**x.59**| β₯ x.59.0 and < x.59.21| **x.59.21**
**x.60**| β₯ x.60.0 and < x.60.17| **x.60.17**
**x.61**| β₯ x.61.0 and < x.61.11| **x.61.11**
**x.62**| β₯ x.62.0 and < x.62.9| **x.62.9**
**x.63**| β₯ x.63.0 and < x.63.5| **x.63.5**
> Versions **below 58** are **not affected**.
* * *
## π οΈ Remediation
### 1\. Upgrade Immediately (Recommended)
Upgrade to the fixed version corresponding to your major release:
Version| OSS Docker| OSS JAR| Enterprise
---|---|---|---
**63**| `metabase/metabase:v0.63.5`| Download| v1.63.5
**62**| `metabase/metabase:v0.62.9`| Download| v1.62.9
**61**| `metabase/metabase:v0.61.11`| Download| v1.61.11
**60**| `metabase/metabase:v0.60.17`| Download| v1.60.17
**59**| `metabase/metabase:v0.59.21`| Download| v1.59.21
**58**| `metabase/metabase:v0.58.24`| Download| v1.58.24
### 2\. Temporary Workaround
If you cannot upgrade immediately, **block access** to the vulnerable endpoint:
root@kitploit:~
/api/session/reset_password
* * *
## π Detection & Indicators of Compromise
Look for this characteristic attack pattern in your application or ingress logs:
root@kitploit:~
POST /api/session/reset_password β 400
GET /api/user/current β 200
If this sequence appears, your instance is **likely compromised**.
### Post-Upgrade Actions (Highly Recommended)
After upgrading, perform the following:
1. **Invalidate all sessions**
root@kitploit:~
TRUNCATE TABLE core_session;
2. Review and delete any unrecognized **API keys**
3. Audit **administrator accounts** for unexpected changes
4. **Rotate credentials** for all connected databases
5. Review data warehouse logs for unauthorized access
6. Examine Metabase activity & query history for anomalies
* * *
## π Official References
* Metabase Security Advisory (GHSA-vwf4-m7j8-wcjf)
* Metabase Official Blog Post
* CVE Record
* CISA Known Exploited Vulnerabilities Catalog
* * *
## β οΈ Disclaimer
This document is provided for **defensive and informational purposes only**.
Always verify information against official vendor advisories.
**Upgrade now. Every unpatched instance remains a high-value target.**
```