CVE-2026-72898 - Metabase SQL injection via password reset endpoint
CVE ID :CVE-2026-72898
Published : Aug. 10, 2026, 6:18 p.m. | 1 hour, 9 minutes ago
Description :Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 10, 2026, 6:18 p.m. | 1 hour, 9 minutes ago
Description :Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...