← All CVEs NewScan detects
critical

CVE-2026-72898

Metabase unauthenticated SQL injection to administrator (/api/session/reset_password, and public-link field filters)

Severity
critical
Affected product
Metabase
Affected versions
Metabase ≥ 0.58.0, < 0.58.24
Affected versions
Metabase ≥ 1.58.0, < 1.58.24
Affected versions
Metabase ≥ 0.59.0, < 0.59.21
Affected versions
Metabase ≥ 1.59.0, < 1.59.21
Affected versions
Metabase ≥ 0.60.0, < 0.60.17
Affected versions
Metabase ≥ 1.60.0, < 1.60.17
Affected versions
Metabase ≥ 0.61.0, < 0.61.11
Affected versions
Metabase ≥ 1.61.0, < 1.61.11
Affected versions
Metabase ≥ 0.62.0, < 0.62.9
Affected versions
Metabase ≥ 1.62.0, < 1.62.9
Affected versions
Metabase ≥ 0.63.0, < 0.63.5
Affected versions
Metabase ≥ 1.63.0, < 1.63.5
Fixed in
Metabase 0.58.24
Fixed in
Metabase 1.58.24
Fixed in
Metabase 0.59.21
Fixed in
Metabase 1.59.21
Fixed in
Metabase 0.60.17
Fixed in
Metabase 1.60.17
Fixed in
Metabase 0.61.11
Fixed in
Metabase 1.61.11
Fixed in
Metabase 0.62.9
Fixed in
Metabase 1.62.9
Fixed in
Metabase 0.63.5
Fixed in
Metabase 1.63.5
Added to NewScan
2026-08-11
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.

Metabase's unauthenticated SQL-injection pair of 2026-08-11: CVE-2026-72898 (CVSS 10.0, GHSA-vwf4-m7j8-wcjf) injects SQL through /api/session/reset_password with no session at all and yields administrator access; CVE-2026-72899 (9.6, GHSA-r8h2-qpfx-mx59) reaches the same application database through a field-filter (dimension) parameter of a PUBLICLY shared card or dashboard, so knowing a public share link is the only precondition. ONE row per branch for both ids because a single release train fixes both, so two rows per branch would be two findings that say 'upgrade to the same version' - noise, not coverage. Metabase writes its advisory ranges as `x.58.0` because the OSS series is 0.x and the Enterprise series is 1.x with the SAME minor/patch numbering, hence the deliberate 0.x + 1.x row pair per branch; the version arrives from the tech_signatures `version_from` on /api/session/properties, which publishes the tag as `v0.58.23`. GHSA-vwf4 lists its affected range as < x.58.23 while naming x.58.24 as the patched build; the row uses the fix-train boundary, so on exactly .23 the finding is right (72899 applies) and one id broad. Version-match only: neither bug can be confirmed in-band without injecting SQL into someone's application database.

COMPONENT VERSION RANGE

NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.

The 1.58.x branch of the 2026-08-11 Metabase SQLi pair. See the 0.58 row for the full advisory, the two-series rationale and the fix-train boundary.

COMPONENT VERSION RANGE

NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.

The 0.59.x branch of the 2026-08-11 Metabase SQLi pair. See the 0.58 row for the full advisory, the two-series rationale and the fix-train boundary.

COMPONENT VERSION RANGE

NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.

The 1.59.x branch of the 2026-08-11 Metabase SQLi pair. See the 0.58 row for the full advisory, the two-series rationale and the fix-train boundary.

COMPONENT VERSION RANGE

NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.

The 0.60.x branch of the 2026-08-11 Metabase SQLi pair. See the 0.58 row for the full advisory, the two-series rationale and the fix-train boundary.

COMPONENT VERSION RANGE

NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.

The 1.60.x branch of the 2026-08-11 Metabase SQLi pair. See the 0.58 row for the full advisory, the two-series rationale and the fix-train boundary.

COMPONENT VERSION RANGE

NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.

The 0.61.x branch of the 2026-08-11 Metabase SQLi pair. See the 0.58 row for the full advisory, the two-series rationale and the fix-train boundary.

COMPONENT VERSION RANGE

NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.

The 1.61.x branch of the 2026-08-11 Metabase SQLi pair. See the 0.58 row for the full advisory, the two-series rationale and the fix-train boundary.

COMPONENT VERSION RANGE

NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.

The 0.62.x branch of the 2026-08-11 Metabase SQLi pair. See the 0.58 row for the full advisory, the two-series rationale and the fix-train boundary.

COMPONENT VERSION RANGE

NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.

The 1.62.x branch of the 2026-08-11 Metabase SQLi pair. See the 0.58 row for the full advisory, the two-series rationale and the fix-train boundary.

COMPONENT VERSION RANGE

NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.

The 0.63.x branch of the 2026-08-11 Metabase SQLi pair. See the 0.58 row for the full advisory, the two-series rationale and the fix-train boundary.

COMPONENT VERSION RANGE

NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.

The 1.63.x branch of the 2026-08-11 Metabase SQLi pair. See the 0.58 row for the full advisory, the two-series rationale and the fix-train boundary.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →