CVE-2026-72898
CRITICAL
CVSS: 10.0
EPSS: 94.2%
VulnCheck KEV
Weaponized
CWE-89
T1190
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.
Published: 2026-08-10