Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-72898

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.011
EPSS Ranking 61.9%
CVSS Severity
CVSS v3 Score 10.0
Proposed Action
Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.
Ransomware Campaign
Unknown
Products affected by CVE-2026-72898


Contact Us

Shodan ® - All rights reserved