SQL Injection Vulnerability in Metabase by Metabase, Inc.
CVE-2026-72898
10CRITICAL
What is CVE-2026-72898?
Metabase contains a vulnerability that enables a remote, unauthenticated attacker to perform SQL injection through the '/reset_password' endpoint. This flaw allows attackers to manipulate database queries, potentially gaining unauthorized administrator access to the Metabase instance and compromising sensitive data.
Affected Version(s)
Metabase x.58.0
Metabase x.59.0
Metabase x.60.0
