chiprook
← Security
SecuritySeptember 25, 2026, 10:20

Metabase CVE-2026-72898: unauthenticated SQL injection exposes the data warehouse

Metabase patched CVE-2026-72898, a CVSS 10.0 SQL injection in the user-id field of the /api/session/reset_password endpoint. CISA added it to the Known Exploited Vulnerabilities catalog on 11 August 2026 with a 14 August remediation deadline. Fixes are available in 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9 and 0.63.5.

Metabase CVE-2026-72898: unauthenticated SQL injection exposes the data warehouse
#Metabase#CISA#Wiz
Read next
Security

VikingCloud: 86% of chains attacked, 77% saw attacks spread across sites

Security

ZoomEye finds 2.7 million Home Assistant installs exposed online

Security

LiteLLM auth bypass: a one-character token unlocked MCP tools

Security

Codex Desktop flaw let untrusted code read auth tokens from shared memory