VENDOR
Metabase vulnerabilities: CVEs, exploitation and patches
Every Metabase CVE reviewed by Diras Labs analysts, newest first, with exploitation status and fixes.
-
CVE-2026-72898
Metabase SQL injection in reset_password allows remote admin takeoverCRITICAL 10
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
No CVEs on this page match the filters.
1 CVEs · page 1 of 1