CVE-2026-72898
Metabase
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.
- CVSS
- 10
- EPSS
- - - percentile
- CISA KEV
- Listed
- Published
- 2026.08.11