← back
CVE-2026-72898criticalunder attackCWE-89

Metabase SQL injection via password reset endpoint

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA, has a working public exploit and 1 threat group(s) use it.

ssvc Actcvss 10epss 94%
from disclosure to weapon2 days
Published on NVDAug 10
1st PoC+2d
CISA KEV+1d
victimsSep 7
exploitation probability
94%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 group(s)13 public exploit(s)
Appeared in 4 incident(s) we investigated
Mathspace · Trezor (via ShipMonk) · Bits of Gold · Trezor (via ShipMonk)
Who exploits it — 1

Groups known to exploit this vulnerability (MITRE ATT&CK attribution).

Action required by CISAfederal deadline: 2026-08-14

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

In short

An attacker can inject malicious SQL code through Metabase's password reset feature without needing to log in, allowing them to take over the system as an administrator.

Technical detail

A SQL injection vulnerability exists in the '/reset_password' endpoint that accepts unsanitized input and executes it directly against the database. An unauthenticated attacker can exploit this to bypass authentication controls and escalate privileges to administrator level, resulting in complete system compromise.

Summary generated and translated by AI from the official description.
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Affected products
Metabase · Metabase
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.