CVE-2026-72898: Metabase SQL Injection Vulnerability

Critical severity, CVSS 10.0. Actively exploited: in CISA KEV since 2026-08-11. EPSS: 19% chance of exploitation in the next 30 days.

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

Affected products

  • Metabase Metabase: from 0.58.0, before 0.58.24 (fixed in 0.58.24); from 0.59.0, before 0.59.21 (fixed in 0.59.21); from 0.60.0, before 0.60.17 (fixed in 0.60.17); from 0.61.0, before 0.61.11 (fixed in 0.61.11); from 0.62.0, before 0.62.9 (fixed in 0.62.9); from 0.63.0, before 0.63.5 (fixed in 0.63.5); …

Published 2026-08-10. Last modified 2026-08-12.