CVE detail
CVE-2026-72898
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.9 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 11
- within the 30d window
- Peak daily
- 5
- highest bucket
Evidence
Source links by recency
11 source links · newest first
CVE-2026-72898 is a critical pre-authentication SQL injection vulnerability affecting Metabase. NodeZero® Rapid Response safely validates whether the actively exploited vulnerability is exploitable in your environment.
exploithorizon3.aiAug 13, 2026, 5:45 PM- U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs
ucture Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-20349 is a vulnerability in Cisco Secure Firewall ASA and FTD software that could allow unauthenticated, […]
newssecurityaffairs.comAug 13, 2026, 5:12 PM - U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs
ucture Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-20349 is a vulnerability in Cisco Secure Firewall ASA and FTD software that could allow unauthenticated, […]
newssecurityaffairs.comAug 13, 2026, 5:12 PM ls, tokens, API keys, and other data may have been exposed. The Metabase vulnerability revealed on August 6, designated CVE-2026-72898 , is identified as critical, with a severity score of 10, the highest possible rating. It is present in versions 1.58 and up. “You don’t see a perfect 10/10 on CVSS often, but when you do, be worried,” noted David Shipl
newswww.csoonline.comAug 12, 2026, 2:40 AMee new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) Heap Inspection Vulnerability CVE-2026-68820 Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
governmentwww.cisa.govAug 11, 2026, 12:00 PMNo excerpt available.
Mitigationwww.cisa.govAug 10, 2026, 6:18 PM- https://www.metabase.com/blog/security-updatewww.metabase.com
No excerpt available.
Technical Descriptionwww.metabase.comAug 10, 2026, 6:18 PM No excerpt available.
Third Party Advisorywww.cve.orgAug 10, 2026, 6:18 PM- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-222-01.jsonraw.githubusercontent.com
No excerpt available.
Exploitraw.githubusercontent.comAug 10, 2026, 6:18 PM No excerpt available.
Exploitgithub.comAug 10, 2026, 6:18 PMpayment information was accessed. Exactly three years ago, Metabase moved to address another "extremely severe" flaw ( CVE-2023-38646 , CVSS score: 9.8) that could have resulted in pre-authenticated remote code execution on affected installations. Additional Victims Emerge N8n, a popular workflow automation platform, disclosed on August 8, 2026, that
newsthehackernews.comAug 8, 2026, 6:58 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-16007CVSS 7.1 · High
AppFlowy's qcuiknote feature is affected by a SQL injection vulnerability. Authenticated users with access to the feature can inject arbitrary SQL to exfiltrate data in the underl…
- CVE-2026-18387CVSS 6.5 · Medium
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'tag_query' parameter in all versions up to, and in…
- CVE-2026-16586CVSS 6.5 · Medium
The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Second-Order SQL Injection via MultipleFiles Second-Order Payloa…
- CVE-2026-16146CVSS 4.9 · Medium
The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to generic SQL Injection via Pattern JSON Keys/Values in all versions up…
- CVE-2026-16094CVSS 4.9 · Medium
The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to generic SQL Injection via the 'key' parameter in all versions up to,…
- CVE-2026-15993CVSS 5.3 · Medium
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to blind SQL Injection via '{username}' Placeholder in Dynamic-Choice…