VENDOR

Metabase vulnerabilities: CVEs, exploitation and patches

Every Metabase CVE reviewed by Diras Labs analysts, newest first, with exploitation status and fixes.

  1. CVE-2026-72898
    Metabase SQL injection in reset_password allows remote admin takeover Metabase Metabase ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 10
1 CVEs · page 1 of 1