CVE-2026-72899Disclosure

MEDIUMCVSS 10.0 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) parameter.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-08-11); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-08-11: 3Mentions · 2026-08-16: 1PoC Mentioned / Linked · 2026-08-11: 1PoC Mentioned / Linked · 2026-08-16: 1Active Exploitation · 2026-08-16: 1Patch / Workaround · 2026-08-11: 1Patch / Workaround · 2026-08-16: 1Technical Details · 2026-08-11: 3Technical Details · 2026-08-16: 108-1108-16
Signal classification3 categories
Disclosure
250.0%
PoC
125.0%
Patch
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-08-113
Disclosure2PoC1
2026-08-161
Patch1
Full discourse4 posts
  • 1dayexploit@1dayexploit
    PoC

    🔥 Metabase: Unauthenticated SQL Injection to Admin Takeover Analysis 🔴 CVE-2026-72898 & CVE-2026-72899 🔴 🗓️ Publish Date: 10 Aug 2026 ÂLIM rebuilt both, wrote a proof of concept for each, and confirmed it fires on the vulnerable build and stays silent on the patched one. Metabase has patched CVE-2026-72898 and CVE-2026-72899. Both are unauthenticated SQL injection. Neither one needs a password, a token, or a click. 🔎 Full Technical Analysis and PoCs: CVE-2026-72898: https://1dayexploit.com/blog/cve-2026-72898-metabase-sql-injection-admin-takeover CVE-2026-72899: https://1dayexploit.com/blog/cve-2026-72899-metabase-sql-injection/ Fixed in 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9 and 0.63.5. -- #Metabase #1dayexploit #ALIM #SQLInjection #RedTeam #OffSec #VulnerabilityResearch #CyberSecurity #InfoSec #AppSec #Exploit

    Post summary

    Proof‑of‑concept code for two unauthenticated SQL injection CVEs in Metabase is provided, the bugs enable admin takeover, and the vendor has issued patches for the affected releases.

    04030369
    46 followersView on X
  • lee1981@lee1981b
    Patch

    🔥 CyberForge CVE of the Day #025 🚨 CVE-2026-72898 — Metabase Unauthenticated SQL Injection to Admin Takeover Metabase has patched a maximum-severity SQL injection that was actively exploited as a zero-day. An unauthenticated remote attacker can target the public password-reset endpoint, inject arbitrary SQL into the Metabase application database and obtain administrator access. 🔑 Key details ⭐ Severity: Critical — CVSS 10.0 ⭐ CWE-89: SQL Injection ⭐ Authentication: None ⭐ User interaction: None ⭐ Attack complexity: Low ⭐ Active exploitation: Confirmed ⭐ CISA KEV: Yes — deadline already passed ⭐ Public weaponised PoCs: Available 🎯 Vulnerable endpoint: POST /api/session/reset_password Successful takeover could allow attackers to alter configuration, create privileged access, steal stored database credentials, query connected data sources and export sensitive information. 🧩 Minimum safe releases • 0/1.58.24 • 0/1.59.21 • 0/1.60.17 • 0/1.61.11 • 0/1.62.9 • 0/1.63.5 🕵️ Official compromise pattern • POST /api/session/reset_password → HTTP 400 • Followed by GET /api/user/current → HTTP 200 Metabase warns that finding this sequence in application or ingress logs means the instance is likely compromised. 🛡️ Defender action: Patch immediately, block the vulnerable endpoint until the upgrade is verified, revoke every active session, audit administrators and API keys, rotate all connected-database credentials, and inspect Metabase plus data-warehouse logs for unauthorised queries or exports. ⚠️ Important: This is not CVE-2026-72899, which targets field filters on publicly shared dashboards. ⚔️ CyberForge verdict: Maximum priority—patch, contain and investigate. Patching stops future exploitation; it does not remove forged sessions or recover stolen credentials. 🔗 Full advisory: https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf #CVE #CVE202672898 #Metabase #SQLInjection #AdminTakeover #ZeroDay #CISAKEV #CyberSecurity #IncidentResponse #ThreatHunting #PatchNow #CyberForge

    Post summary

    The advisory confirms that Metabase’s CVE‑2026‑72898, a critical SQL injection, is actively exploited; it provides patch releases, mitigation guidance, and references to weaponised PoCs, urging immediate remediation.

    00010188
    559 followersView on X
  • SecAlerts@SecAlertsCo
    Disclosure

    🗃️ Metabase CVE-2026-72899: unauthenticated SQL injection via public card or dashboard field-filter params. CVSS 10. No auth, no interaction needed. If you share Metabase content publicly, assume exposure. #cybersecurity #ciso #cto #vulnerabilities #msp https://secalerts.co/vulnerability/CVE-2026-72899?utm_campaign=x https://t.co/VV9zBX7Udd

    Post summary

    An unauthenticated, high‑severity SQL injection vulnerability (CVE‑2026‑72899) affecting public Metabase cards and dashboards has been disclosed, with no authentication or user interaction required.

    00010186
    877 followersView on X
  • NewNormal Security@NewScanTeam
    Disclosure

    NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 11 Aug 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 💉 Unauthenticated SQL injection in a BI dashboard — SQL with no login at all, ending in an admin account (Metabase CVE-2026-72898, Metabase CVE-2026-72899) ⚡ Pre-auth RCE via a public setup token — reads the setup secret served to anonymous callers, then runs commands on the host (Metabase CVE-2023-38646) 🖥️ Analytics install that was never set up — whoever reaches it first claims the admin account, and every database credential added to it later (Metabase) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve&s=x #infosec #AppSec #SQLi #CSO #REDTEAM

    Post summary

    The post announces new Metabase vulnerabilities (unauthenticated SQLi and pre-auth RCE) with CVE references, detailing technical aspects but offering no PoC, exploit, patch, or evidence of active use.

    00000158
    5 followersView on X

Explore more