Vulnerability
Published 2026-08-06
Verified 2026-09-19

Metabase unauth SQLi to admin (CVE-2026-72898); CVSS 10.0; exploited in the wild

Metabase GHSA-vwf4-m7j8-wcjf (published 6 August 2026; CVE-2026-72898) is an unauthenticated SQL injection on /api/session/reset_password that lets a remote attacker inject SQL into the Metabase application database and obtain administrator access, then steal connected-database credentials and export data. CVSS 3.1 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Metabase confirmed active exploitation. Affected OSS lines include ≥0.58.0 before the patched builds; fixed releases are 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9 and 0.63.5 (Enterprise 1.x counterparts on the same minors). Temporary workaround: block /api/session/reset_password. After upgrade on a previously exposed instance: delete core_session rows, review API keys and admin accounts, rotate connected-database credentials, and review warehouse and Metabase query history. This CVE is the Metabase flaw referenced in the Mathspace AU/NZ education breach and in third-party reporting on the ShipMonk/Trezor supply-chain incident. Primary: Metabase GitHub security advisory.

Product
Metabase (self-hosted)
Versions
≥0.58.0 lines before 0.58.24 / 0.59.21 / 0.60.17 / 0.61.11 / 0.62.9 / 0.63.5 (see GHSA; Enterprise 1.x on same minors)
CVSS
(CVSS 3.1, GHSA)
Exploited in Australia?
yes
Patch to
0.58.24; 0.59.21; 0.60.17; 0.61.11; 0.62.9; 0.63.5 (or Enterprise 1.x equivalents); then session/API/credential review per GHSA

Primary: Metabase GHSA-vwf4-m7j8-wcjf · Vendor: Metabase — August 2026 vulnerability post · CVE: CVE-2026-72898 · NVD CVE-2026-72898

vulnerabilities cloud australia