Junglewise Threat Intelligence

CVE-2026-72898: Metabase SQL injection in password reset endpoint

CVE-2026-72898 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2026-08-11

Executive brief

Metabase, a popular business intelligence and data visualization platform, contains a critical security flaw that allows unauthorized individuals to take full control of the system. By exploiting this vulnerability, an attacker can gain administrator privileges without needing a password, allowing them to steal sensitive business data, access connected databases, and modify system configurations. This vulnerability is currently being exploited in the wild, posing an immediate risk to data confidentiality and operational integrity.

Technical details

A SQL injection vulnerability (CWE-89) exists in the Metabase '/reset_password' endpoint due to improper neutralization of special elements in SQL commands. An unauthenticated remote attacker can exploit this by sending crafted requests to the vulnerable endpoint, allowing for arbitrary SQL execution against the application database. Successful exploitation enables the attacker to escalate privileges to administrator, modify application settings, and extract credentials for all connected data sources. The vulnerability is confirmed to be exploited in the wild, and users are advised to update to version x.58.24 or later.

Affected products

  • Metabase Metabase x.58.0 to x.58.24

Timeline

  • 2026-08-10: disclosed
  • 2026-08-11: advisory
  • 2026-08-11: kev added: CISA added to Known Exploited Vulnerabilities catalog
  • 2026-08-11: exploited

Related threats