CVE-2026-72898: Metabase SQL Injection Vulnerability
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.
CSIRTS triage
- What
- SQL injection vulnerability in Metabase's password reset endpoint allows unauthenticated remote attackers to gain administrator access and retrieve connected database credentials.
- Who is affected
- Internet-exposed Metabase instances with the vulnerable reset endpoint accessible.
- Urgency
- Critical; actively exploited, unauthenticated remote access, CVSS 10, full administrative compromise.
- Action
- Patch Metabase immediately to the latest version containing the fix for CVE-2026-72898.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Metabase
Get an email when a new Metabase advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-72898
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-72898Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 99.8% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-72898 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownexploitedVulnérabilité dans Metabase (10 septembre 2026)cert-fr-alerte
- unknownexploitedMultiple vulnerabilities in Metabase (August 24, 2026)cert-fr-avis
- highexploitedCISA Adds Three Known Exploited Vulnerabilities to Catalogcisa
- criticalexploitedCVE-2026-72898: Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_pas…nvd
Recent advisories for Metabase SQL Injection
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- critical[NEW] [critical] Metabase: Vulnerability enables SQL injection and privilege escalationcert-bund · 2026-08-11
- criticalCVE-2026-72899: Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card…nvd · 2026-08-10
- criticalexploitedCVE-2026-72898: Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_pas…nvd · 2026-08-10
More from CISA Known Exploited Vulnerabilities
- criticalCVE-2026-67277: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability2026-09-10
- criticalCVE-2026-86060: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability2026-09-10
- criticalCVE-2026-19490: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability2026-09-09
- criticalCVE-2025-25249: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability2026-09-09
- criticalCVE-2026-20079: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vuln…2026-09-09