Metabase CVE-2026-72898: unauthenticated SQL injection exposes the data warehouse
Metabase patched CVE-2026-72898, a CVSS 10.0 SQL injection in the user-id field of the /api/session/reset_password endpoint. CISA added it to the Known Exploited Vulnerabilities catalog on 11 August 2026 with a 14 August remediation deadline. Fixes are available in 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9 and 0.63.5.
- CVSS 3.1 score of 10.0, CWE-89, exploitable without authentication
- CISA KEV listing on 11 August, three-day deadline of 14 August
- Patched releases: 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, 0.63.5
- Wiz estimated roughly 2,500 internet-exposed Metabase instances
Read next
Security