Vulnerability Details CVE-2026-72898
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 49.5%
CVSS Severity
CVSS v3 Score 10.0
Proposed Action
Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.
Ransomware Campaign
Unknown