CVE-2026-72898
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.
- Published Aug 10, 2026
- CVSS 10.0 critical
- 19.0% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
- A fix is available
Affected software
In the news
- Vulnerability in Metabase CERT-FR ·
- SQL injection vulnerability in Metabase (CVE-2026-72898) JPCERT/CC ·