CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-72898

KEV Critical · CVSS 10.0
CVSS
10.0
nvd
EPSS
1.07%
62th pct
KEV
Listed
2026-08-11
Class
other
CWE-89

Description

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

References

Status: profiled · ingested 2026-08-12T18:00:50.000Z