CVE-2026-72898
CRITICAL
NVD
CVSS Score
10
Severity
CRITICAL
Published
Aug 10, 2026
Vendor
unknown
Description
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.