Critical severity10.0CISA KEVNVD Advisory· Published Aug 10, 2026· Updated Aug 12, 2026
CVE-2026-72898
CVE-2026-72898
Description
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- osv-coords3 versionspkg:apk/chainguard/metabase-oci-entrypointpkg:apk/chainguard/metabase-compatpkg:apk/chainguard/metabase
< 0.63.2-r1+ 2 more
- (no CPE)range: < 0.63.2-r1
- (no CPE)range: < 0.63.2-r1
- (no CPE)range: < 0.63.2-r1
Patches
Vulnerability mechanics
References
5- github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjfnvdMitigationPatchVendor Advisory
- www.metabase.com/blog/security-updatenvdMitigationPatchVendor Advisory
- raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-222-01.jsonnvdThird Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
- www.cve.org/CVERecordnvdVDB Entry
News mentions
5- 14th September – Threat Intelligence ReportCheck Point Research · Sep 14, 2026
- Mathspace Data Breach Exposes Over 1 Million PeopleSecurityWeek · Sep 8, 2026
- Online Maths Learning Platform Mathspace Disclosed Data Breach Impacts 1 Million UsersCyber Security News · Sep 7, 2026
- Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was DeletedThe Hacker News · Sep 5, 2026
- CISA Adds Three Known Exploited Vulnerabilities to CatalogCISA Alerts