CVE-2026-72898
Known exploited · CISA KEV
CVSS 10 CRITICAL: metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database…
CISA federal remediation date Aug 14
Vulnerabilities · 47 days ago
CSIRT Italia said on August 11 that Metabase CVE-2026-72898 is being actively exploited in the wild, while NCSC-NL separately issued a Power BI Server advisory for CVE-2026-65811. Metabase’s fixes cover affected x.58 through x.63 branches.
The Metabase flaw sits in the password-reset path: attacker-supplied SQL can slip past the login checks and land an attacker in an admin session. Once inside, Metabase can expose the database credentials it stores for connected systems, so the problem is not limited to the dashboard itself.
For teams that use BI tools as the front end to internal data, the durable exposure is whatever databases the platform can already reach. The Power BI issue is a different class of problem: it needs prior authentication and, unlike Metabase, was not reported as exploited.
Known exploited · CISA KEV
CVSS 10 CRITICAL: metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database…
CISA federal remediation date Aug 14
CVSS 8.8 HIGH: improper input validation in Power BI allows an authorized attacker to execute code over a network. Microsoft patch: Release Notes.
7 sources covering this story
Kwetsbaarheid verholpen in Microsoft Power BI server
Microsoft heeft een kwetsbaarheid verholpen in Power BI server.
Risolte vulnerabilità in Metabase
Tra queste si evidenzia la CVE-2026-72898, che risulta sfruttata attivamente in rete.
Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius
The max-severity vuln, which still has no CVE, allows malicious, remote administrator access to the business-analytics platform and its downstream users.
Metabase zero-day exploited to access Framework customer data - Help Net Security
Framework has suffered a data breach after attackers managed to exploit a zero-day vulnerability in its Metabase cloud instance.
Inside the Metabase SQLi: Exploited in the Wild | Wiz Blog
Reverse engineering Metabase CVE-2026-72898 with AI to accelerate defense.
Metabase Patches Vulnerability Exploited as Zero-Day
The security defect allows unauthenticated, remote attackers to gain administrative access to Metabase instances.
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
Metabase says a CVSS 10.0 zero-day SQL injection was exploited in the wild; the flaw can grant admin access and expose connected database data.
Part of the PlainSec briefing for 2026-08-10