CVE-2026-72898
CRITICAL KEVMetabase SQL injection via password reset endpoint
Title source: cnaExploitation Summary
CVE-2026-72898 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added August 11, 2026.
Description
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.
References (5)
Core 5
Core References
Vendor Advisory vendor-advisory
url
https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf
Third Party Advisory third-party-advisory
url
https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-222-01.json
Third Party Advisory, US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-72898
Scores
CVSS v3
10.0
EPSS
0.0069
EPSS Percentile
49.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
active
Automatable
yes
Technical Impact
total
Details
CISA KEV
2026-08-11
VulnCheck KEV
2026-08-06
ENISA EUVD
EUVD-2026-55690
CWE
CWE-89
Status
published
Products (12)
Metabase/Metabase
x.58.0 - x.58.24
Metabase/Metabase
x.58.24
Metabase/Metabase
x.59.0 - x.59.21
Metabase/Metabase
x.59.21
Metabase/Metabase
x.60.0 - x.60.17
Metabase/Metabase
x.60.17
Metabase/Metabase
x.61.0 - x.61.11
Metabase/Metabase
x.61.11
Metabase/Metabase
x.62.0 - x.62.9
Metabase/Metabase
x.62.9
... and 2 more
Published
Aug 10, 2026
KEV Added
Aug 11, 2026
Tracked Since
Aug 11, 2026