CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-72898: Metabase SQL Injection Vulnerability

criticalknown exploitedpublic exploitCVE-2026-72898
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.

CSIRTS triage

What
SQL injection vulnerability in Metabase's password reset endpoint allows unauthenticated remote attackers to gain administrator access and retrieve connected database credentials.
Who is affected
Internet-exposed Metabase instances with the vulnerable reset endpoint accessible.
Urgency
Critical; actively exploited, unauthenticated remote access, CVSS 10, full administrative compromise.
Action
Patch Metabase immediately to the latest version containing the fix for CVE-2026-72898.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Metabase

Get an email when a new Metabase advisory drops — max one per day, one-click unsubscribe.

Details

Source
CISA Known Exploited Vulnerabilities (US · database · site)
Severity
critical
Published
2026-08-11
Exploitation
Observed in the wild (CISA KEV)

Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-72898

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-72898coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Metabase SQL Injection

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from CISA Known Exploited Vulnerabilities