CVE-2026-72898Active Exploitation(metabase / metabase)

CRITICALCVSS 10.0 · CRITICALCISA KEV

Exploitation observed; activity peaked at 16 mentions and remains active

Immediate actions

  • Patch metabase metabase systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-08-14. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-89

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • metabase

Threat summary

  • Active exploitation appears in 71 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 126 mentions across 34 observed days

What's happening

  • Active exploitation reported across 71 signals
  • Exploit tool or code specified in 10 signals
  • PoC mentioned or linked in 19 signals
  • Patch or workaround mentioned in 52 signals
  • Technical details provided in 99 signals
  • Disclosure: 18 classified signals
  • General: 14 classified signals
  • Peaked 32d ago at 16 mentions (2026-08-12); latest day: 1
  • 126 total mentions across 34 days

Affected systems

Vendors
Products
metabase

Deep dive

Activity timeline126 mentions / 34d
0481216Mentions · 2026-08-11: 7Mentions · 2026-08-12: 16Mentions · 2026-08-13: 16Mentions · 2026-08-14: 15Mentions · 2026-08-15: 1Mentions · 2026-08-16: 9Mentions · 2026-08-17: 6Mentions · 2026-08-18: 4Mentions · 2026-08-19: 1Mentions · 2026-08-20: 3Mentions · 2026-08-21: 1Mentions · 2026-08-22: 2Mentions · 2026-08-24: 2Mentions · 2026-08-25: 7Mentions · 2026-08-26: 3Mentions · 2026-08-27: 4Mentions · 2026-08-28: 4Mentions · 2026-08-29: 1Mentions · 2026-08-30: 2Mentions · 2026-09-01: 1Mentions · 2026-09-03: 1Mentions · 2026-09-05: 2Mentions · 2026-09-06: 1Mentions · 2026-09-07: 3Mentions · 2026-09-08: 2Mentions · 2026-09-09: 2Mentions · 2026-09-10: 2Mentions · 2026-09-11: 2Mentions · 2026-09-12: 1Mentions · 2026-09-13: 1Mentions · 2026-09-14: 1Mentions · 2026-09-19: 1Mentions · 2026-09-22: 1Mentions · 2026-09-23: 1PoC Mentioned / Linked · 2026-08-11: 2PoC Mentioned / Linked · 2026-08-12: 1PoC Mentioned / Linked · 2026-08-13: 1PoC Mentioned / Linked · 2026-08-14: 2PoC Mentioned / Linked · 2026-08-16: 2PoC Mentioned / Linked · 2026-08-17: 1PoC Mentioned / Linked · 2026-08-18: 1PoC Mentioned / Linked · 2026-08-25: 2PoC Mentioned / Linked · 2026-08-26: 1PoC Mentioned / Linked · 2026-08-27: 2PoC Mentioned / Linked · 2026-08-28: 1PoC Mentioned / Linked · 2026-08-30: 1PoC Mentioned / Linked · 2026-09-08: 2Exploit Tool / Code · 2026-08-11: 2Exploit Tool / Code · 2026-08-12: 1Exploit Tool / Code · 2026-08-13: 1Exploit Tool / Code · 2026-08-14: 1Exploit Tool / Code · 2026-08-17: 1Exploit Tool / Code · 2026-08-18: 1Exploit Tool / Code · 2026-08-26: 1Exploit Tool / Code · 2026-08-27: 1Exploit Tool / Code · 2026-08-28: 1Active Exploitation · 2026-08-11: 3Active Exploitation · 2026-08-12: 11Active Exploitation · 2026-08-13: 11Active Exploitation · 2026-08-14: 9Active Exploitation · 2026-08-15: 1Active Exploitation · 2026-08-16: 6Active Exploitation · 2026-08-17: 2Active Exploitation · 2026-08-18: 1Active Exploitation · 2026-08-19: 1Active Exploitation · 2026-08-20: 2Active Exploitation · 2026-08-22: 1Active Exploitation · 2026-08-24: 2Active Exploitation · 2026-08-25: 5Active Exploitation · 2026-08-26: 1Active Exploitation · 2026-08-27: 1Active Exploitation · 2026-08-28: 1Active Exploitation · 2026-08-30: 2Active Exploitation · 2026-09-03: 1Active Exploitation · 2026-09-05: 1Active Exploitation · 2026-09-06: 1Active Exploitation · 2026-09-07: 2Active Exploitation · 2026-09-08: 1Active Exploitation · 2026-09-09: 1Active Exploitation · 2026-09-10: 2Active Exploitation · 2026-09-11: 2Patch / Workaround · 2026-08-11: 5Patch / Workaround · 2026-08-12: 7Patch / Workaround · 2026-08-13: 8Patch / Workaround · 2026-08-14: 8Patch / Workaround · 2026-08-16: 5Patch / Workaround · 2026-08-17: 3Patch / Workaround · 2026-08-20: 2Patch / Workaround · 2026-08-25: 2Patch / Workaround · 2026-08-26: 1Patch / Workaround · 2026-08-27: 2Patch / Workaround · 2026-08-28: 2Patch / Workaround · 2026-08-29: 1Patch / Workaround · 2026-08-30: 1Patch / Workaround · 2026-09-07: 2Patch / Workaround · 2026-09-08: 1Patch / Workaround · 2026-09-09: 1Patch / Workaround · 2026-09-11: 1Technical Details · 2026-08-11: 7Technical Details · 2026-08-12: 13Technical Details · 2026-08-13: 13Technical Details · 2026-08-14: 13Technical Details · 2026-08-16: 8Technical Details · 2026-08-17: 3Technical Details · 2026-08-18: 3Technical Details · 2026-08-19: 1Technical Details · 2026-08-20: 3Technical Details · 2026-08-21: 1Technical Details · 2026-08-22: 1Technical Details · 2026-08-24: 2Technical Details · 2026-08-25: 5Technical Details · 2026-08-26: 2Technical Details · 2026-08-27: 4Technical Details · 2026-08-28: 3Technical Details · 2026-08-29: 1Technical Details · 2026-08-30: 2Technical Details · 2026-09-01: 1Technical Details · 2026-09-03: 1Technical Details · 2026-09-05: 1Technical Details · 2026-09-06: 1Technical Details · 2026-09-07: 3Technical Details · 2026-09-08: 1Technical Details · 2026-09-09: 2Technical Details · 2026-09-10: 2Technical Details · 2026-09-11: 208-1108-1408-1708-2008-2408-2708-3009-0509-0809-1109-1409-23
Signal classification6 categories
Active Exploitation
6654.5%
Disclosure
1814.9%
General
1411.6%
Patch
1411.6%
PoC
75.8%
Exploit
21.7%
Referenced assets90 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-117
Active Exploitation3General1Patch2PoC1
2026-08-1216
Active Exploitation9Disclosure3Exploit1General1Patch2
2026-08-1316
Active Exploitation11Disclosure2General1Patch1
2026-08-1415
Active Exploitation9Disclosure3General1Patch2
2026-08-151
Active Exploitation1
2026-08-169
Active Exploitation5Disclosure2Patch2
2026-08-176
Active Exploitation2Exploit1General2Patch1
2026-08-184
Active Exploitation1Disclosure1General1PoC1
2026-08-191
Active Exploitation1
2026-08-203
Active Exploitation2Patch1
2026-08-211
Disclosure1
2026-08-222
Active Exploitation1
2026-08-242
Active Exploitation2
2026-08-257
Active Exploitation5Disclosure1General1
2026-08-263
Active Exploitation1Disclosure1PoC1
2026-08-274
Active Exploitation1Disclosure1Patch1PoC1
2026-08-284
Active Exploitation1Disclosure2PoC1
2026-08-291
Disclosure1
2026-08-302
Active Exploitation1PoC1
2026-09-011
General1
2026-09-031
Active Exploitation1
2026-09-052
Active Exploitation1General1
2026-09-061
Active Exploitation1
2026-09-073
Active Exploitation2Patch1
2026-09-082
Active Exploitation1PoC1
2026-09-092
General1Patch1
2026-09-102
Active Exploitation2
2026-09-112
Active Exploitation2
2026-09-121
General1
2026-09-131
General1
2026-09-141
General1
Full discourse20 posts
  • Dhiyaneshwaran@DhiyaneshDK
    Disclosure

    🚨 CVE-2026-72898 - Metabase - Unauthenticated SQL Injection Nuclei Template: https://cloud.projectdiscovery.io/library/CVE-2026-72898 Reference: https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf #hackwithautomation #nuclei https://t.co/3GxQcklaiG

    Post summary

    A newly disclosed unauthenticated SQL injection in Metabase (CVE‑2026‑72898) is reported, with a Nuclei template provided for detection and a link to the official advisory.

    480145926221.5K
    4.8K followersView on X
  • OffSec@offsectraining
    Active Exploitation

    🚨 CVE-2026-72898: A critical unauthenticated SQL injection vulnerability in Metabase is being actively exploited. The vulnerability affects the password-reset flow and can ultimately allow an attacker to gain administrator access to a vulnerable Metabase instance. Our latest technical breakdown covers: → How CVE-2026-72898 works → Affected Metabase versions → The exploitation flow and potential impact → What defenders should look for → Mitigation steps → How to safely validate the vulnerability in OffSec’s Offensive Cyber Range Read the full analysis: https://bit.ly/4gh2qYA Explore the lab: https://bit.ly/3SnaI87 #CVE #Cybersecurity #Metabase #VulnerabilityResearch #OffSec

    Post summary

    CVE‑2026‑72898 is a critical unauthenticated SQL injection in Metabase’s password‑reset flow that is reportedly being actively exploited, with detailed technical analysis and mitigation recommendations provided.

    464335213424.9K
    331.1K followersView on X
  • OffSec@offsectraining
    Active Exploitation

    🚨 ICYMI: CVE-2026-72898: Critical Metabase SQL injection, CVSS 10.0, no authentication required — and active exploitation has been confirmed. See how it works, what to look for, how to mitigate it, and how to safely test it in OffSec's Offensive Cyber Range. Explore the lab: https://portal.offsec.com/machine/cve-2026-72898-247730/overview #CVE #Cybersecurity #Metabase #VulnerabilityResearch #OffSec

    Post summary

    The post announces CVE-2026-72898, a critical Metabase SQL injection, confirms active exploitation in the wild, and directs users to a lab for mitigation and testing.

    42811305315.9K
    331.1K followersView on X
  • Cyberattaque.org@CyberattaqueOrg
    Disclosure

    ‼️ L’État expose encore aujourd’hui une version vulnérable de Metabase. Docurba utilise toujours la 0.63.2, vulnérable à CVE-2026-72898 (CVSS 10/10), pourtant corrigée depuis le 6 août. Et deux fuites liées à des environnements de l’État utilisant Metabase viennent d’être revendiquées. 20 jours sans correctif c’est inacceptable.

    Post summary

    The tweet highlights that a state entity still runs Metabase 0.63.2, which is vulnerable to CVE‑2026‑72898 (CVSS 10/10) and has been patched since Aug 6, while noting recent leaks linked to these environments.

    5282821710.4K
    164 followersView on X
  • 国家サイバー統括室(注意・警戒情報)@cyber_forecast
    Disclosure

    【注意喚起】 2026年8月14日、MetabaseのSQLインジェクションの脆弱性(CVE-2026-72898)について、JPCERT/CCが注意喚起をしています。ご確認ください。 https://x.com/jpcert/status/2088127391914930498

    Post summary

    JPCERT/CC has issued an advisory warning about a SQL injection vulnerability (CVE‑2026‑72898) in Metabase, directing users to review the details via the provided link.

    143173816.3K
    101.5K followersView on X
  • FOFA@fofabot
    Patch

    ⚠️⚠️ CVE-2026-72898 (CVSS 10.0): Metabase Unauthenticated SQL Injection Zero-Day 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJNZXRhYmFzZSI%3D 🎯113.9K+ results on http://en.fofa.info FOFA Query: app="Metabase" 🔖Refer: https://www.metabase.com/blog/security-update #OSINT #FOFA #CyberSecurity #Vulnerability #Metabase https://t.co/vEGEmcDL4T

    Post summary

    The tweet announces CVE-2026-72898, a critical unauthenticated SQL injection in Metabase, and references the vendor’s patch/update page.

    126068238.9K
    14.8K followersView on X
  • ANSSI@ANSSI_FR
    Active Exploitation

    ⚠️ Vulnérabilité Metabase 📢 Le CERT-FR publie une alerte de sécurité ayant connaissance de compromissions de Metabase vulnérables à l'injection SQL CVE-2026-72898. Plus d'informations sur : ➡️ https://www.cert.ssi.gouv.fr/alerte/CERTFR-2026-ALE-010/ https://t.co/Tqd5Qfp84S

    Post summary

    CERT‑FR alerts that Metabase is being actively exploited via an SQL injection flaw (CVE‑2026‑72898), with known compromises reported. Users should consult the linked alert for details.

    117134932.0K
    84.4K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-72898 - critical 🚨 Metabase - Unauthenticated SQL Injection > Metabase contains a sql injection caused by improper sanitization of input in the '/r... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-72898 @pdnuclei #NucleiTemplates #cve

    Post summary

    The message announces the new CVE-2026-72898, identifies it as an unauthenticated SQL Injection in Metabase, and provides a link to further information, but does not mention exploitation, patches, or false positives.

    07033101.8K
    1.3K followersView on X
  • Dark Web Intelligence@DailyDarkWeb
    PoC

    🚨 WORKING PoC CLAIMED FOR METABASE SQL INJECTION — CVE-2026-72898 A threat actor on an underground cybercrime forum claims to have released working proof-of-concept code targeting CVE-2026-72898, described in the post as a SQL injection vulnerability affecting Metabase. According to the actor, the PoC supports: * Full database extraction * Mass scanning of potentially vulnerable hosts * Attempts to escalate exploitation to remote code execution * Automated targeting of Metabase instances The actor further claims to have already obtained: * 600+ Metabase databases * 50+ RCE sessions running with PostgreSQL user privileges The actor also threatens to publish data and access obtained from affected systems. ⚠️ Analyst Note: The appearance of operational exploit code on a cybercrime forum can materially increase exploitation risk, particularly if it enables automated discovery and database extraction. However, the actor's claims regarding 600+ compromised databases and 50+ RCE sessions remain unverified. The claimed RCE capability should also not be treated as an inherent consequence of the SQL injection without technical validation. Organizations operating Metabase should urgently determine whether their deployments are affected by CVE-2026-72898, apply the vendor's remediation where applicable, restrict unnecessary Internet exposure, and investigate Metabase/PostgreSQL environments for signs of exploitation. #DDW #Metabase #CVE202672898 #SQLInjection #PoC #CyberSecurity #ThreatIntelligence

    Post summary

    A forum post claims a working PoC for CVE‑2026‑72898 with alleged active exploitation of over 600 Metabase instances; while evidence remains unverified, the PoC’s existence elevates risk, urging urgent patching and containment.

    1402797.3K
    205.0K followersView on X
  • Hunter@HunterMapping
    Disclosure

    🚨Alert🚨 CVE-2026-72898(0-day , CVSS 10.0) : A SQL injection Vulnerability exposed through Metabase’s Password-Reset Functionality. It affects versions 1.58 and above. 📊 302.8K Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22Metabase%22 HUNTER : http://product.name="Metabase" 📰Refer:https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf https://www.metabase.com/blog/security-update #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    The post announces a newly disclosed high‑severity SQL injection vulnerability (CVE‑2026‑72898) in Metabase, referencing vendor advisories that indicate available patches.

    07017103.8K
    26.1K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️We added Cisco Secure Firewall vulnerability CVE-2026-20349, Microsoft Windows vulnerability CVE-2026-68820 & Metabase vulnerability CVE-2026-72898 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity https://t.co/iahRvhwOoT

    Post summary

    Three new CVEs were added to the KEV Catalog, signaling the vulnerabilities are actively exploited; users are urged to apply mitigations for protection.

    27022210.1K
    302.6K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    PoC

    🔴 EQSTLab tarafından CVE-2026-72898 - Metabase password reset endpoint'indeki unauthenticated SQL Injection açığı için PoC yayınlandı! PoC: https://github.com/EQSTLab/CVE-2026-72898 https://t.co/qL5poYQWtL

    Post summary

    EQSTLab released a proof‑of‑concept for CVE‑2026‑72898, revealing an unauthenticated SQL injection in Metabase’s password‑reset endpoint, with the PoC publicly available on GitHub.

    0601291.1K
    2.4K followersView on X
  • Horizon3.ai@Horizon3ai
    Active Exploitation

    🚨 CVSS 10.0. Pre-auth SQLi. Actively exploited. Rapid Response test now available for Metabase CVE-2026-72898. https://t.co/U5g1sjV5Xq

    Post summary

    CVE‑2026‑72898 is a high‑severity, pre‑authentication SQLi vulnerability (CVSS 10.0) that is reportedly being actively exploited, and a Rapid Response test is now available.

    1311371.1K
    3.0K followersView on X
  • JPCERTコーディネーションセンター@jpcert
    Active Exploitation

    MetabaseのSQLインジェクションの脆弱性(CVE-2026-72898)に関する注意喚起を公開。本脆弱性を悪用したゼロデイ攻撃が確認されており、概念実証(PoC)コードとみられる情報も確認されています。脆弱性の対策に加え、侵害有無の調査、必要な対処の実施をご検討ください。^KK https://www.jpcert.or.jp/at/2026/at260023.html

    Post summary

    The notice confirms CVE-2026-72898 is actively exploited in real‑world zero‑day attacks and that a PoC has been published, but it does not provide a patch or detailed mitigation steps.

    05313121.3K
    34.3K followersView on X
  • FUITES INFOS@fuitesinfos
    Active Exploitation

    Nos 3 hypothèses sur ce leak : Extraction verrouillée sur l'UI Metabase (cap à 2 000 lignes sur 6 tables = limite raw-query par défaut ; instance Metabase citée en colonne source ; mise en forme post-export par script Python). Reste l'entrée. CVE-2026-72898 → session valide. SQLi non-auth (CVSS 10) sur la base applicative Metabase → récupération des secrets de connexion / jetons de session → extraction via UI authentifiée. Réconcilie la faille et le cap à 2 000. Timeline cohérente (avis 06/08, exploits publics 10/08, dernière écriture 14/08 ; même acteur, même empreinte que imapper). Instance Metabase exposée / auth faible. Tableau de bord interne joignable sans CVE. Explique le cap à 2 000 seul. Non corroboré par le relevé de surface. Compte légitime compromis (phishing / credential stuffing). Même signature UI + cap 2 000, sans faille ni exposition. Indistinguable de (1) côté données une fois la session ouverte. Note : une SQLi pure ne produirait pas le plafond à 2 000 → argue contre l'exfiltration directe, pour un accès UI. Départage impossible depuis le corpus (montre la sortie, pas l'entrée)

    Post summary

    The text reports active exploitation of CVE‑2026‑72898 via non‑auth SQL injection to exfiltrate secrets through Metabase’s authenticated UI, noting public exploits but no patches or PoC links.

    12095977
    5.2K followersView on X
  • piyokango@piyokango
    General

    MetabaseのSQLインジェクションの脆弱性(CVE-2026-72898)に関する注意喚起 https://www.jpcert.or.jp/at/2026/at260023.html

    Post summary

    The notice announces a SQL injection flaw in Metabase (CVE-2026-72898) but provides no PoC, exploit details, or patch information.

    0201325.5K
    44.3K followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-72898 Vendor: Metabase Product: Metabase Description: Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance. Link: https://github.com/4minx/cve-2026-72898 #dbugs_vuln

    Post summary

    A proof‑of‑concept and exploit code for CVE‑2026‑72898, enabling remote unauthenticated SQL injection through Metabase's '/reset_password' endpoint, has been released on GitHub.

    000133980
    3.6K followersView on X
  • The Shadowserver Foundation@Shadowserver
    Active Exploitation

    We are also scanning & reporting Metabase IPs likely unpatched to CVE-2026-72898 SQLi, which is exploited in the wild & on @CISACyber KEV. 2171 unpatched (version check) instances seen 2026-08-15. Top US (603), Germany (278) Dashboard World Map stats: https://dashboard.shadowserver.org/statistics/combined/map/?date_range=1&map_type=std&source=http_vulnerable&source=http_vulnerable6&tag=cve-2026-72898%2B&data_set=count&scale=log&auto_update=on https://t.co/7atIEFR3LQ

    Post summary

    The post reports that 2,171 Metabase instances are unpatched to CVE-2026-72898, a SQL injection flaw that is actively exploited in the wild, as confirmed by CISA KEV.

    150622.0K
    22.0K followersView on X
  • CERT-FR@CERT_FR
    Active Exploitation

    ⚠️Alerte CERT-FR⚠️ Le CERT-FR a connaissance de nombreuses compromissions de Metabase vulnérables à l'injection SQL CVE-2026-72898. https://www.cert.ssi.gouv.fr/alerte/CERTFR-2026-ALE-010/

    Post summary

    The alert confirms that Metabase is being actively exploited via a SQL injection vulnerability (CVE‑2026‑72898), as reported by CERT‑FR.

    4215115.4K
    58.2K followersView on X
  • Bishop Fox@bishopfox
    Active Exploitation

    🚨 Critical Metabase SQL injection (CVE-2026-72898) CVSS 10.0. No authentication required. Actively exploited in the wild. https://t.co/yLbkDNdcSC

    Post summary

    Metabase SQL injection CVE-2026-72898, rated CVSS 10.0, requires no authentication and is actively exploited; no patch or PoC is referenced.

    110821.1K
    26.3K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appmetabasemetabase---
Appmetabasemetabase---

Explore more