CVE-2026-72898: Metabase allows a remote, unauthenticated attacker to
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.
- CISA KEV-listed (remediation due 2026-08-14)
- EPSS 79.2% (99.6% percentile)
- CVSS 10 critical