DIRAS TAKE
Urgent — CISA placed this flaw on its Known Exploited Vulnerabilities list with a required mitigation date, and public exploit code exists, so prioritize patching or blocking access to the reset_password endpoint immediately.
What is CVE-2026-72898?
Remote, unauthenticated attackers can exploit CVE-2026-72898 to inject SQL via Metabase's /reset_password endpoint and obtain administrator access to a Metabase instance. The vulnerability affects Metabase branches from x.58.0 through releases before the fixed builds: x.58.24, x.59.21, x.60.17, x.61.11, x.62.9 and x.63.5. An attacker only needs network access to the vulnerable endpoint; no valid account or user interaction is required to attempt exploitation. The weakness is classified as CWE-89 (SQL Injection).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Which versions of Metabase Metabase are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Metabase | x.58.0 – before x.58.24 | x.58.24 |
| Metabase | x.59.0 – before x.59.21 | x.59.21 |
| Metabase | x.60.0 – before x.60.17 | x.60.17 |
| Metabase | x.61.0 – before x.61.11 | x.61.11 |
| Metabase | x.62.0 – before x.62.9 | x.62.9 |
| Metabase | x.63.0 – before x.63.5 | x.63.5 |
Is CVE-2026-72898 being exploited?
CISA added this issue to the Known Exploited Vulnerabilities catalog on 2026-08-11, and U.S. federal agencies were required to mitigate it by 2026-08-14; public exploit code is also available.
How to fix CVE-2026-72898
- Upgrade Metabase to a fixed release: x.58.24, x.59.21, x.60.17, x.61.11, x.62.9 or x.63.5 as appropriate for your branch.
- If you cannot patch immediately, restrict network access to the Metabase instance and block access to the /reset_password endpoint from untrusted networks.
- Follow Metabase vendor guidance for any additional mitigations and configuration changes.
- Monitor Metabase logs and database access for suspicious queries and indicators of compromise.
Frequently asked questions
Is CVE-2026-72898 being actively exploited?
Yes. CISA added CVE-2026-72898 to its Known Exploited Vulnerabilities catalog on 2026-08-11, federal agencies were required to mitigate it by 2026-08-14, and public exploit code is available.
Which Metabase versions are affected by CVE-2026-72898?
Metabase releases from x.58.0 through versions before the fixes are affected; fixed releases are x.58.24, x.59.21, x.60.17, x.61.11, x.62.9 and x.63.5.
Is there a patch for CVE-2026-72898?
Yes. Metabase published fixed releases; upgrade to one of the listed fixed versions for your branch.
Does CVE-2026-72898 require authentication?
No. The vulnerability can be exploited by an unauthenticated remote attacker via the /reset_password endpoint.
References
- nvd.nist.gov/vuln/detail/CVE-2026-72898
- cve.org/CVERecord?id=CVE-2026-72898
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-72898
- github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf
- metabase.com/blog/security-update
- raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-222-01.json
- All Metabase CVEs on CVE Radar
- CVEs published in September 2026