CVE Tools

Critical SQL Injection in Metabase via Password Reset: CVE-2026-72898

Bishop FoxBy Threat Enablement & Analysis Team3 min read

Reported exploitedMetabase

Our summary

Metabase has confirmed active exploitation of a critical, unauthenticated SQL injection vulnerability identified as CVE-2026-72898. This flaw in the password reset endpoint allows attackers to execute arbitrary SQL queries against the application database without requiring prior credentials. Organizations running self-hosted instances should immediately update to the fixed versions, including 58.24, 59.21, 60.17, 61.11, 62.9, or 63.5 and their respective later releases.

Read at Bishop Fox

Below is the opening; the full story is at Bishop Fox.

From Bishop Fox

TL;DR:

Immediate action is advised for all organizations running self-hosted Metabase. A critical, unauthenticated SQL injection vulnerability has been disclosed in Metabase's password reset functionality, and Metabase has confirmed active exploitation in the wild.

Overview

The vulnerability, tracked as GHSA-vwf4-m7j8-wcjf, affects the unauthenticated POST /api/session/reset_password endpoint in Metabase. CVE designation: CVE-2026-72898">CVE-2026-72898.…

Continue at Bishop Fox

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store