Vulnerabilities
Vulnerable Software
Metabase:  >> Metabase  >> 1.58.15.2  Security Vulnerabilities
CVE-2026-72898
Known exploited
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.
CVSS Score
10.0
EPSS Score
0.104
Published
2026-08-10


Contact Us

Shodan ® - All rights reserved