Permission Bypass in Metabase Affecting Glossary API Endpoints
CVE-2026-86116

7.1HIGH

Key Information:

Vendor

Metabase

Status
Vendor
CVE Published:
5 September 2026

What is CVE-2026-86116?

Metabase versions prior to 0.63.1 exhibit a vulnerability that allows any authenticated user to bypass permission checks on glossary API endpoints. This oversight enables attackers to create, modify, or delete glossary entries, jeopardizing the integrity of instance-wide business glossary data. By exploiting the lack of proper authorization, unauthorized individuals can submit requests for POST, PUT, and DELETE operations, leading to potential data corruption and loss of control over critical business information.

Affected Version(s)

metabase 0.57.0 < 0.63.1

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.