Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.
PoC: CVE-2026-72898
Metabase SQLi
PoC: Metabase-Setup-Endpoint-SQLi-Fix
CVE-2026-72898-Metabase-SQLi-Fix
PoC: CVE-2026-72898
CVE-2026-72898 PoC : Metabase Unauthenticated SQL Injection
PoC: CVE-2026-72898-metabase-sqli
Detector + root-cause analysis for CVE-2026-72898 (Metabase unauthenticated SQLi via reset_password)
PoC: CVE-2026-72898-safe-detection
Simple script to achieve safe and non-desruptive active detection of CVE-2026-72898 (SQLi in Metabase)
PoC: CVE-2026-72898
PoC for CVE-2026-72898
PoC: CVE-2026-72898-PoC
CVE-2026-72898 - Metabase
PoC: CVE-2026-72898
CVE-2026-72898
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free