← Vulnerability feed

Vulnerability record · CVE-2026-72898 · published 10 August 2026

CVE-2026-72898: Metabase unauthenticated SQL injection in reset_password endpoint

Metabase · Metabase

Metabase exposes a database endpoint, '/reset_password', that fails to neutralize attacker-supplied SQL, allowing arbitrary SQL injection. Because the endpoint is reachable without authentication, any remote attacker who can reach the instance can abuse it to take over the connected Metabase instance. The flaw is a classic CWE-89 injection with full confidentiality, integrity and availability impact per the CVSS 4.0 vector.

10.0 CVSS 4.0 Critical CISA KEV since 11 Aug 2026 EPSS 19% · top 2.8% CWE-89 · SQL injection
10.0CVSS 4.0 base score
19%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References
12 Aug 2026Last modified by NVD

Description

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated remote SQL injection leading to admin takeover, CVSS 10.0, KEV-listed with known exploitation and a near-maximum EPSS score.

What it is

Metabase exposes a database endpoint, '/reset_password', that fails to neutralize attacker-supplied SQL, allowing arbitrary SQL injection. Because the endpoint is reachable without authentication, any remote attacker who can reach the instance can abuse it to take over the connected Metabase instance. The flaw is a classic CWE-89 injection with full confidentiality, integrity and availability impact per the CVSS 4.0 vector.

Impact

An attacker gains administrator access to the Metabase instance and can read or modify the connected data sources and configuration. With admin control, they can pivot to the underlying database and any data Metabase can reach.

Attack surface

Reached over the network via the '/reset_password' endpoint; the CVSS vector shows PR:N and UI:N, so no authentication or user interaction is required. Any internet-exposed Metabase instance is directly reachable.

Exploitation

CVE-2026-72898 was added to CISA KEV on 2026-08-11 with a remediation due date of 2026-08-14, indicating known exploitation. EPSS is 0.94217 (99.8th percentile), and vendor references are tagged Patch and Mitigation.

What to do

  • Apply the vendor patch from the Metabase security advisory GHSA-vwf4-m7j8-wcjf and the Metabase security update blog immediately.
  • If patching is not possible, restrict network access to the '/reset_password' endpoint and remove internet exposure of Metabase instances.
  • Follow CISA BOD 26-04 guidance, including discontinuing use of the product if mitigations are unavailable.
  • Rotate credentials and secrets for the Metabase instance and its connected databases after patching, assuming compromise.
  • Review Metabase admin accounts and configuration for unauthorized changes made before remediation.

Detection

  • Search web and proxy logs for requests to '/reset_password' with SQL metacharacters or unexpected parameters.
  • Monitor Metabase audit logs for new or modified admin accounts and privilege changes.
  • Alert on outbound database queries from the Metabase host that deviate from normal application behavior.
  • Correlate KEV/EPSS-driven scanning activity against exposed Metabase instances with authentication and configuration events.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-72898 to the Known Exploited Vulnerabilities catalog on 11 August 2026 as "Metabase SQL Injection Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 14 August 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-72898 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2021-41277Metabase custom GeoJSON map feature allows local file inclusionMetabase does not validate URLs supplied through the custom GeoJSON map setting (admin->settings->maps->custom maps->add a map) before loading them. …KEVEPSS 97%analysed9.8CVE-2023-37470Metabase code injection vulnerabilityMetabase is an open-source business intelligence and analytics platform. Prior to versions 0.43.7.3, 0.44.7.3, 0.45.4.3, 0.46.6.4, 1.43.7.3, 1.44.7.3…EPSS 1.3%9.8CVE-2023-38646Metabase unauthenticated remote command executionMetabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server at the serve…EPSS 99%analysed9.6CVE-2023-32680Metabase missing authentication for critical function vulnerabilityMetabase is an open source business analytics engine. To edit SQL Snippets, Metabase should have required people to be in at least one group with nat…EPSS 0.60%9.1CVE-2026-50148Metabase vulnerabilityMetabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10,…EPSS 0.77%9.1CVE-2026-59826Metabase code injection vulnerabilityMetabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2, Metabase di…EPSS 1.0%8.8CVE-2026-59827Metabase deserialization of untrusted data vulnerabilityMetabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances w…EPSS 3.8%8.8CVE-2022-39362Metabase vulnerabilityMetabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, unsaved SQL queries ar…EPSS 0.86%

Source: NIST National Vulnerability Database (record CVE-2026-72898), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.