Critical CVSS 10.0 SQL injection in Metabase allows unauthenticated admin access. Active exploitation reported. Patch affected versions immediately.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| metabase | 0.58.0 | 0.58.24 | vulnerable |
| metabase | 0.59.0 | 0.59.21 | vulnerable |
| metabase | 0.60.0 | 0.60.17 | vulnerable |
| metabase | 0.61.0 | 0.61.11 | vulnerable |
| metabase | 0.62.0 | 0.62.9 | vulnerable |
| metabase | 0.63.0 | 0.63.5 | vulnerable |
| metabase | 1.58.0 | 1.58.24 | vulnerable |
| metabase | 1.59.0 | 1.59.21 | vulnerable |
| metabase | 1.60.0 | 1.60.17 | vulnerable |
| metabase | 1.61.0 | 1.61.11 | vulnerable |
| metabase | 1.62.0 | 1.62.9 | vulnerable |
| metabase | 1.63.0 | 1.63.5 | vulnerable |
Immediately update your Metabase installation to the latest available security release. Vendor patches have been issued for all major release branches including 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, and 0.63.5 (and their corresponding 1.x versions).
Identify all Metabase instances running vulnerable versions between 0.58.0 and 0.63.4. Ensure that the update process covers all environments, including production, staging, and containerized deployments, to eliminate the SQL injection vector.
Place Metabase instances behind a VPN or firewall and restrict access to the web interface to known, trusted IP addresses. Use a Web Application Firewall (WAF) to filter malicious SQL injection patterns targeting the '/reset_password' endpoint.
Review application logs for unusual POST requests to the password reset endpoint and audit database logs for unauthorized queries. Following CISA BOD 26-04, perform a forensic triage to ensure no administrative accounts were compromised prior to patching.
"Detecting exploitation of CVE-2026-72898 involves monitoring web server and WAF logs for HTTP POST requests to the '/api/user/reset_password' endpoint containing SQL injection signatures such as '--', 'UNION SELECT', or unexpected semicolons. Security teams should also inspect Metabase audit logs for the creation of new, unauthorized administrator accounts and check database engine logs for anomalous queries executed by the Metabase service account."
Experience superior visibility and a simpler approach to cyber risk management