CVE-2026-72898
Known exploited · CISA KEV
CVSS 10 CRITICAL: metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database…
CISA federal remediation date Aug 14 · date passed
Vulnerabilities & Exploits · Web App Attack
JPCERT/CC said October 8 that a cluster of recent Japanese personal-data leaks involved both mobile app API abuse and exploitation of Metabase, the BI tool behind some of the exposed systems. The alert names no attacker or victim, but it says the incidents centered on web systems and employee-facing tools operators did not expect to be public.
The Metabase flaw, CVE-2026-72898, lets an attacker trick the password-reset database endpoint into running attacker-supplied SQL without logging in. In a connected Metabase instance, that can be enough to reach administrator access, so a compromise that starts at a public app or API can jump into the BI layer and the data it can see.
That matters for teams that treat customer-facing APIs and internal reporting tools as separate estates. If a public endpoint can reach a backend BI or management system, the blast radius is the store of data and admin control behind it, not just the front-end app that first took the hit.
1 source · 6h ago
Known exploited · CISA KEV
CVSS 10 CRITICAL: metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database…
CISA federal remediation date Aug 14 · date passed
The Hacker News
Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks
JPCERT/CC links Japan's recent data leaks to mobile API abuse and known software flaws, including an exploited Metabase SQL injection bug.
originalPart of the PlainSec briefing for 2026-10-08
Every edition of this story: JPCERT ties Japanese leaks to Metabase SQL injection