CVE-2026-72898 – Metabase

CVSS 10 CRITICAL Zero Day – Immediate Deployment

“Active exploitation of a maximum-severity SQL injection flaw puts exposed Metabase instances at immediate risk of administrative takeover.”

CVE-2026-72898 is a Critical SQL injection vulnerability affecting Metabase. The CVSS score is 10.0, which is Critical severity. A remote unauthenticated attacker can inject arbitrary SQL through the /reset_password database endpoint and gain administrator access to the connected Metabase instance.

The vulnerability is actively exploited, making unpatched and externally accessible deployments a significant compromise risk.

Key Details

Affected Product
Metabase Metabase
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-89
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.