Permission Bypass in Metabase Affecting Glossary API Endpoints
CVE-2026-86116
7.1HIGH
What is CVE-2026-86116?
Metabase versions prior to 0.63.1 exhibit a vulnerability that allows any authenticated user to bypass permission checks on glossary API endpoints. This oversight enables attackers to create, modify, or delete glossary entries, jeopardizing the integrity of instance-wide business glossary data. By exploiting the lack of proper authorization, unauthorized individuals can submit requests for POST, PUT, and DELETE operations, leading to potential data corruption and loss of control over critical business information.
Affected Version(s)
metabase 0.57.0 < 0.63.1
