P.01Cybersecurity/Vulnerability Management··5 min read
CVE-2026-72898: Metabase's Password-Reset Endpoint Lets Anyone Become Admin
An unauthenticated attacker can inject SQL through Metabase's password-reset flow and walk out with full admin access. CVSS 10.0, on CISA's KEV list since August 11. Here's what's affected and how to patch it.
CybersecurityCVESQL Injection
Read