Metabase SQL injection flaw CVE-2026-72898 grants admin access without login
A critical unauthenticated SQL injection vulnerability, CVE-2026-72898, was discovered in Metabase, a widely used business intelligence platform that stores database credentials for connected data warehouses. The flaw exists in the password-reset endpoint's user-id parameter, which passes unsanitised input into a query, allowing attackers to forge an administrator session via a crafted SQL payload without needing any credentials. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on 11 August 2026, setting a federal remediation deadline of just three days. The threat group ShinyHunters has been linked to active exploitation, with affected organisations including Mathspace, which reported over one million students and staff impacted across Australia and New Zealand. Patched versions are available across six Metabase release lines from 0.58 through 0.63, and security experts stress that patching must be followed by credential rotation to fully contain any breach.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in