logo

Warning: Actively exploited SQL injection in Metabase, Patch Immediately!

ID: f33c4ceb-97dd-51f8-b2c0-cacb0af29a20

STIX ID: report--f33c4ceb-97dd-51f8-b2c0-cacb0af29a20

Feed Name: Centre for Cybersecurity Belgium Advisories Feed

Threat Score
95/100

Date Published: 2026-08-13

Date Updated: 2026-08-13

...
...

A critical SQL injection vulnerability (CVE-2026-72898, CVSS 10.0) in multiple Metabase versions allows unauthenticated remote attackers to inject arbitrary SQL via the /api/session/reset_password endpoint, obtain administrator access, steal stored database credentials, and read or export connected data; the vendor confirms active exploitation and recommends immediate patching to specified fixed versions or blocking the endpoint as a temporary workaround.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.