CVE-2026-72898

Analyzed
Published: 10 Aug 2026, 17:55
Last modified:12 Aug 2026, 14:50

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
10 CRITICAL
v4.0 (cve.org)
EPSS Score
10.4% MEDIUM
10% probability +9.33%
KEV
Listed
CISA
1 listing
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

10 Aug 2026, 17:55
Published
Vulnerability first disclosed
11 Aug 2026, 00:00
Added to CISA KEV
Metabase SQL Injection Vulnerability
12 Aug 2026, 14:50
Last Modified
Vulnerability information updated
14 Aug 2026, 00:00
CISA Remediation Due
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Description

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

CVSS Metrics

  • v4.0CRITICALScore: 10CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
  • v4.0CRITICALScore: 10CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.1CRITICALScore: 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 10.40% Percentile: 95%

Techniques & Countermeasures

  • CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

    The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Affected Systems

  • metabasemetabase

    ≥ x.58.0, < x.58.24 | ≥ x.59.0, < x.59.21 | ≥ x.60.0, < x.60.17 | ≥ x.61.0, < x.61.11 | ≥ x.62.0, < x.62.9 | ≥ x.63.0, < x.63.5 | ≥ 0.58.0, < 0.58.24 | ≥ 0.59.0, < 0.59.21 | ≥ 0.60.0, < 0.60.17 | ≥ 0.61.0, < 0.61.11 | ≥ 0.62.0, < 0.62.9 | ≥ 0.63.0, < 0.63.5 | ≥ 1.58.0, < 1.58.24 | ≥ 1.59.0, < 1.59.21 | ≥ 1.60.0, < 1.60.17 | ≥ 1.61.0, < 1.61.11 | ≥ 1.62.0, < 1.62.9 | ≥ 1.63.0, < 1.63.5

References (5)