CVE-CVE-2026-72898
Severity
CRITICAL
CVSS Score
10.0
Description
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance....
PoCs for CVE-CVE-2026-72898
CVE-2026-72898-PoC
General
0
codeb0ssx
2026-08-13
CVE-2026-72898-metabase-sqli
SQL Injection
Python
0
d-maggipinto
2026-08-26
CVE-2026-72898
General
Python
0
34zY
2026-09-14