Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-72898

Published 2026-08-10
Updated 15 days ago
Vendor/s
Metabase
Product/s
Metabase
Version/s
0.58.0 > 0.58.24
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
10
/ 10
Critical
Severity Details
Base score
10 Critical
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Description

Critical CVSS 10.0 SQL injection in Metabase allows unauthenticated admin access. Active exploitation reported. Patch affected versions immediately.

CPE

Metabase logo
Metabase
Product Version Start Version End (excl.) Status
metabase 0.58.0 0.58.24 vulnerable
metabase 0.59.0 0.59.21 vulnerable
metabase 0.60.0 0.60.17 vulnerable
metabase 0.61.0 0.61.11 vulnerable
metabase 0.62.0 0.62.9 vulnerable
metabase 0.63.0 0.63.5 vulnerable
metabase 1.58.0 1.58.24 vulnerable
metabase 1.59.0 1.59.21 vulnerable
metabase 1.60.0 1.60.17 vulnerable
metabase 1.61.0 1.61.11 vulnerable
metabase 1.62.0 1.62.9 vulnerable
metabase 1.63.0 1.63.5 vulnerable

Related weakness (CWE)

CWE-89

Remediation plan

1

Apply official patches

Immediately update your Metabase installation to the latest available security release. Vendor patches have been issued for all major release branches including 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, and 0.63.5 (and their corresponding 1.x versions).

2

Update affected systems

Identify all Metabase instances running vulnerable versions between 0.58.0 and 0.63.4. Ensure that the update process covers all environments, including production, staging, and containerized deployments, to eliminate the SQL injection vector.

3

Restrict access

Place Metabase instances behind a VPN or firewall and restrict access to the web interface to known, trusted IP addresses. Use a Web Application Firewall (WAF) to filter malicious SQL injection patterns targeting the '/reset_password' endpoint.

4

Monitor for exploitation

Review application logs for unusual POST requests to the password reset endpoint and audit database logs for unauthorized queries. Following CISA BOD 26-04, perform a forensic triage to ensure no administrative accounts were compromised prior to patching.

Detection Guidance

"Detecting exploitation of CVE-2026-72898 involves monitoring web server and WAF logs for HTTP POST requests to the '/api/user/reset_password' endpoint containing SQL injection signatures such as '--', 'UNION SELECT', or unexpected semicolons. Security teams should also inspect Metabase audit logs for the creation of new, unauthorized administrator accounts and check database engine logs for anomalous queries executed by the Metabase service account."

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management