CVE-2026-72898: Metabase SQL injection via password reset endpoint
Published Aug 10, 2026
·Updated
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/resetpassword' database endpoint and gain administrator access to the connected Metabase instance.
Affected Software
1 affected component
Metabase
Event History
Aug 10, 2026
CVE Published
via MITRE·05:55 PM
Data Sourced
via MITRE·05:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-72898?
CVE-2026-72898 has been rated with a critical severity score of 10.
2
How do I fix CVE-2026-72898?
To mitigate CVE-2026-72898, ensure you are using the latest version of Metabase that addresses this SQL injection vulnerability.
3
What is the risk associated with CVE-2026-72898?
The risk associated with CVE-2026-72898 is rated at 87, indicating a high likelihood of exploitation.
4
What type of vulnerability is CVE-2026-72898?
CVE-2026-72898 is classified as an SQL Injection vulnerability.
5
How can an attacker exploit CVE-2026-72898?
An attacker can exploit CVE-2026-72898 by sending crafted requests to the '/reset_password' endpoint to inject arbitrary SQL.