Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4992 articles · 188948 vulns · 37/41 feeds (7d)
← Back to list
10.0
CVE-2026-72898KEVEXPLOITEDPATCHED
metaba · metaba

Metabase SQL injection via password reset endpoint

Description

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

Affected Products

VendorProductVersions
metabametabax.58.0, x.59.0, x.60.0, x.61.0, x.62.0, x.63.0

References

  • https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf(vendor-advisory)
  • https://www.metabase.com/blog/security-update(vendor-advisory)
  • https://www.cve.org/CVERecord?id=CVE-2026-72898(vdb-entry)
  • https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-222-01.json(third-party-advisory)
  • https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-72898.yaml(exploit, nuclei)

Related News (2 articles)

Tier D
CSO Online16h ago
Metabase SQLi exploit grants attackers total access
→ No new info (linked only)
Tier C
VulDB2d ago
CVE-2026-72898 | Metabase up to x.63.4 Password Reset sql injection
→ No new info (linked only)
CVSS 3.110.0 NONE
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
x.58.24x.59.21x.60.17x.61.11x.62.9x.63.5
CWECWE-89
PublishedAug 10, 2026
Last enriched2d ago
Trending Score120🔥
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-72899
Metabase SQL injection via public card or dashboard
Trending: 50
MEDIUMCVE-2026-72900
Metabase information exposure
Trending: 30
CRITICALCVE-2026-50148
Metabase: Remote Code Execution via Snowflake JDBC Driver Arbitrary File Write
Trending: 2
HIGHCVE-2026-50147EXP
Metabase: Arbitrary File Read via MySQL Connection Property Injection
Trending: 1
CRITICALCVE-2026-59826EXP
Metabase: Arbitrary Code Execution via Database Connection Detail Bypass

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 10, 2026
Added to CISA KEV
Aug 10, 2026
Discovered by ZDM
Aug 10, 2026
Actively Exploited
Aug 11, 2026
Exploit Available
Aug 11, 2026
Patch Available
Aug 11, 2026