Back to Labs
Security Advisory

CVE-2026-72898

About

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

Weakness (CWE):CWE-89

Rainforest analyst review

Metabase's /reset_password endpoint builds a database query from unsanitized user input, opening a SQL injection reachable remotely and without authentication. By manipulating the injected query an attacker can subvert the application's own logic — forging or resetting authentication state — and grant themselves administrator access to the Metabase instance, all through requests to a single unauthenticated endpoint.

Metabase is a business-intelligence front end wired directly into an organization's databases, so administrative control of it is a bridge to every connected data source: the analytics layer becomes a pivot into the data warehouse itself. Instances are frequently exposed to the internet for convenient dashboard access, widening the target. Upgrade to a fixed release immediately, and because admin access exposes downstream systems, rotate the credentials Metabase uses to reach each connected database, review administrator accounts for unfamiliar additions, and check query and access logs for signs the endpoint was already abused.

References

Related CVEs

Frequently asked questions

What is CVE-2026-72898?

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

How severe is CVE-2026-72898?

CVE-2026-72898 carries a CVSS 3.1 base score of 10, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 100 out of 100, in the critical band.

How is CVE-2026-72898 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.

Which products are affected by CVE-2026-72898?

Public advisories list the following as affected: metabase. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2026-72898?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email