OffSec[verified]@offsectrainingActive Exploitation
CVE‑2026‑72898 is a critical unauthenticated SQL injection in Metabase’s password‑reset flow that is reportedly being actively exploited, with detailed technical analysis and mitigation recommendations provided.
OffSec[verified]@offsectrainingActive Exploitation
The post announces CVE-2026-72898, a critical Metabase SQL injection, confirms active exploitation in the wild, and directs users to a lab for mitigation and testing.
Cyberattaque.org[verified]@CyberattaqueOrgDisclosure
The tweet highlights that a state entity still runs Metabase 0.63.2, which is vulnerable to CVE‑2026‑72898 (CVSS 10/10) and has been patched since Aug 6, while noting recent leaks linked to these environments.
FOFA[verified]@fofabotPatch
The tweet announces CVE-2026-72898, a critical unauthenticated SQL injection in Metabase, and references the vendor’s patch/update page.
Dark Web Intelligence[verified]@DailyDarkWebPoC
A forum post claims a working PoC for CVE‑2026‑72898 with alleged active exploitation of over 600 Metabase instances; while evidence remains unverified, the PoC’s existence elevates risk, urging urgent patching and containment.
Hunter[verified]@HunterMappingDisclosure
The post announces a newly disclosed high‑severity SQL injection vulnerability (CVE‑2026‑72898) in Metabase, referencing vendor advisories that indicate available patches.
Rıdvan Yağlı[verified]@ridvanyagliPoC
EQSTLab released a proof‑of‑concept for CVE‑2026‑72898, revealing an unauthenticated SQL injection in Metabase’s password‑reset endpoint, with the PoC publicly available on GitHub.
Horizon3.ai[verified]@Horizon3aiActive Exploitation
CVE‑2026‑72898 is a high‑severity, pre‑authentication SQLi vulnerability (CVSS 10.0) that is reportedly being actively exploited, and a Rapid Response test is now available.