cbcvebase.
CVE-2026-72898
published 2026-08-10

CVE-2026-72898: Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the…

PriorityP1100critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-08-14
Exploited in the wild
EPSS
79.22%
99.6th percentile
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

Affected

18 ranges
VendorProductVersion rangeFixed in
metabasemetabase>= 0.58.0 < 0.58.240.58.24
metabasemetabase>= 0.59.0 < 0.59.210.59.21
metabasemetabase>= 0.60.0 < 0.60.170.60.17
metabasemetabase>= 0.61.0 < 0.61.110.61.11
metabasemetabase>= 0.62.0 < 0.62.90.62.9
metabasemetabase>= 0.63.0 < 0.63.50.63.5
metabasemetabase>= 1.58.0 < 1.58.241.58.24
metabasemetabase>= 1.59.0 < 1.59.211.59.21
metabasemetabase>= 1.60.0 < 1.60.171.60.17
metabasemetabase>= 1.61.0 < 1.61.111.61.11
metabasemetabase>= 1.62.0 < 1.62.91.62.9
metabasemetabase>= 1.63.0 < 1.63.51.63.5
metabasemetabase>= x.58.0 < x.58.24x.58.24
metabasemetabase>= x.59.0 < x.59.21x.59.21
metabasemetabase>= x.60.0 < x.60.17x.60.17
metabasemetabase>= x.61.0 < x.61.11x.61.11
metabasemetabase>= x.62.0 < x.62.9x.62.9
metabasemetabase>= x.63.0 < x.63.5x.63.5

CVSS provenance

nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv4.010.0CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vulncheck10.0CRITICAL
cisa10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.