• CISA KEV
  • EXPLOITED
  • PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-72898: pre-auth sql injection in Metabase Metabase

Remote, unauthenticated attackers can exploit CVE-2026-72898 to inject SQL via Metabase's /reset_password endpoint and obtain administrator access to a Metabase instance. The vulnerability affects Metabase branches from x.58.0 through releases before the fixed builds: x.58.24, x.59.21, x.60.17, x.61.11, x.62.9 and x.63.5. An attacker only needs network access to the vulnerable endpoint; no valid account or user interaction is required to attempt exploitation.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS, Vendor advisory

CVSS 3.1
10CRITICAL
EPSS
0.19048
CWE
CWE-89
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent — CISA placed this flaw on its Known Exploited Vulnerabilities list with a required mitigation date, and public exploit code exists, so prioritize patching or blocking access to the reset_password endpoint immediately.

What is CVE-2026-72898?

Remote, unauthenticated attackers can exploit CVE-2026-72898 to inject SQL via Metabase's /reset_password endpoint and obtain administrator access to a Metabase instance. The vulnerability affects Metabase branches from x.58.0 through releases before the fixed builds: x.58.24, x.59.21, x.60.17, x.61.11, x.62.9 and x.63.5. An attacker only needs network access to the vulnerable endpoint; no valid account or user interaction is required to attempt exploitation. The weakness is classified as CWE-89 (SQL Injection).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Which versions of Metabase Metabase are affected?

BRANCHAFFECTEDFIXED
Metabasex.58.0 – before x.58.24x.58.24
Metabasex.59.0 – before x.59.21x.59.21
Metabasex.60.0 – before x.60.17x.60.17
Metabasex.61.0 – before x.61.11x.61.11
Metabasex.62.0 – before x.62.9x.62.9
Metabasex.63.0 – before x.63.5x.63.5

Is CVE-2026-72898 being exploited?

CISA added this issue to the Known Exploited Vulnerabilities catalog on 2026-08-11, and U.S. federal agencies were required to mitigate it by 2026-08-14; public exploit code is also available.

How to fix CVE-2026-72898

  1. Upgrade Metabase to a fixed release: x.58.24, x.59.21, x.60.17, x.61.11, x.62.9 or x.63.5 as appropriate for your branch.
  2. If you cannot patch immediately, restrict network access to the Metabase instance and block access to the /reset_password endpoint from untrusted networks.
  3. Follow Metabase vendor guidance for any additional mitigations and configuration changes.
  4. Monitor Metabase logs and database access for suspicious queries and indicators of compromise.

Frequently asked questions

Is CVE-2026-72898 being actively exploited?

Yes. CISA added CVE-2026-72898 to its Known Exploited Vulnerabilities catalog on 2026-08-11, federal agencies were required to mitigate it by 2026-08-14, and public exploit code is available.

Which Metabase versions are affected by CVE-2026-72898?

Metabase releases from x.58.0 through versions before the fixes are affected; fixed releases are x.58.24, x.59.21, x.60.17, x.61.11, x.62.9 and x.63.5.

Is there a patch for CVE-2026-72898?

Yes. Metabase published fixed releases; upgrade to one of the listed fixed versions for your branch.

Does CVE-2026-72898 require authentication?

No. The vulnerability can be exploited by an unauthenticated remote attacker via the /reset_password endpoint.

References