CVE-2026-22805

HIGH

Metabase <55.13, 56.3, 57.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

Metabase is an open-source data analytics platform. Prior to 55.13, 56.3, and 57.1, self-hosted Metabase instances that allow users to create subscriptions could be potentially impacted if their Metabase is colocated with other unsecured resources. This vulnerability is fixed in 55.13, 56.3, and 57.1.

References (1)

Core 1
Core References

Scores

CVSS v3 8.6
EPSS 0.0020
EPSS Percentile 9.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (7)
metabase/metabase 0.57.0 beta
metabase/metabase 1.57.0 beta
metabase/metabase < 0.55.13
metabase/metabase < 1.55.13
metabase/metabase < 55.13
metabase/metabase >= 0.56.0-beta, < 56.3
metabase/metabase >= 0.57.0-beta, < 57.1
Published Jan 12, 2026
Tracked Since Feb 18, 2026