CVE-2026-72898
Metabase unauthenticated SQL injection to administrator (/api/session/reset_password, and public-link field filters)
- Severity
- critical
- Affected product
- Metabase
- Affected versions
- Metabase ≥ 0.58.0, < 0.58.24
- Affected versions
- Metabase ≥ 1.58.0, < 1.58.24
- Affected versions
- Metabase ≥ 0.59.0, < 0.59.21
- Affected versions
- Metabase ≥ 1.59.0, < 1.59.21
- Affected versions
- Metabase ≥ 0.60.0, < 0.60.17
- Affected versions
- Metabase ≥ 1.60.0, < 1.60.17
- Affected versions
- Metabase ≥ 0.61.0, < 0.61.11
- Affected versions
- Metabase ≥ 1.61.0, < 1.61.11
- Affected versions
- Metabase ≥ 0.62.0, < 0.62.9
- Affected versions
- Metabase ≥ 1.62.0, < 1.62.9
- Affected versions
- Metabase ≥ 0.63.0, < 0.63.5
- Affected versions
- Metabase ≥ 1.63.0, < 1.63.5
- Fixed in
- Metabase 0.58.24
- Fixed in
- Metabase 1.58.24
- Fixed in
- Metabase 0.59.21
- Fixed in
- Metabase 1.59.21
- Fixed in
- Metabase 0.60.17
- Fixed in
- Metabase 1.60.17
- Fixed in
- Metabase 0.61.11
- Fixed in
- Metabase 1.61.11
- Fixed in
- Metabase 0.62.9
- Fixed in
- Metabase 1.62.9
- Fixed in
- Metabase 0.63.5
- Fixed in
- Metabase 1.63.5
- Added to NewScan
- 2026-08-11
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.
Metabase's unauthenticated SQL-injection pair of 2026-08-11: CVE-2026-72898 (CVSS 10.0, GHSA-vwf4-m7j8-wcjf) injects SQL through /api/session/reset_password with no session at all and yields administrator access; CVE-2026-72899 (9.6, GHSA-r8h2-qpfx-mx59) reaches the same application database through a field-filter (dimension) parameter of a PUBLICLY shared card or dashboard, so knowing a public share link is the only precondition. ONE row per branch for both ids because a single release train fixes both, so two rows per branch would be two findings that say 'upgrade to the same version' - noise, not coverage. Metabase writes its advisory ranges as `x.58.0` because the OSS series is 0.x and the Enterprise series is 1.x with the SAME minor/patch numbering, hence the deliberate 0.x + 1.x row pair per branch; the version arrives from the tech_signatures `version_from` on /api/session/properties, which publishes the tag as `v0.58.23`. GHSA-vwf4 lists its affected range as < x.58.23 while naming x.58.24 as the patched build; the row uses the fix-train boundary, so on exactly .23 the finding is right (72899 applies) and one id broad. Version-match only: neither bug can be confirmed in-band without injecting SQL into someone's application database.
COMPONENT VERSION RANGE
NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.
The 1.58.x branch of the 2026-08-11 Metabase SQLi pair. See the 0.58 row for the full advisory, the two-series rationale and the fix-train boundary.
COMPONENT VERSION RANGE
NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.
The 0.59.x branch of the 2026-08-11 Metabase SQLi pair. See the 0.58 row for the full advisory, the two-series rationale and the fix-train boundary.
COMPONENT VERSION RANGE
NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.
The 1.59.x branch of the 2026-08-11 Metabase SQLi pair. See the 0.58 row for the full advisory, the two-series rationale and the fix-train boundary.
COMPONENT VERSION RANGE
NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.
The 0.60.x branch of the 2026-08-11 Metabase SQLi pair. See the 0.58 row for the full advisory, the two-series rationale and the fix-train boundary.
COMPONENT VERSION RANGE
NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.
The 1.60.x branch of the 2026-08-11 Metabase SQLi pair. See the 0.58 row for the full advisory, the two-series rationale and the fix-train boundary.
COMPONENT VERSION RANGE
NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.
The 0.61.x branch of the 2026-08-11 Metabase SQLi pair. See the 0.58 row for the full advisory, the two-series rationale and the fix-train boundary.
COMPONENT VERSION RANGE
NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.
The 1.61.x branch of the 2026-08-11 Metabase SQLi pair. See the 0.58 row for the full advisory, the two-series rationale and the fix-train boundary.
COMPONENT VERSION RANGE
NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.
The 0.62.x branch of the 2026-08-11 Metabase SQLi pair. See the 0.58 row for the full advisory, the two-series rationale and the fix-train boundary.
COMPONENT VERSION RANGE
NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.
The 1.62.x branch of the 2026-08-11 Metabase SQLi pair. See the 0.58 row for the full advisory, the two-series rationale and the fix-train boundary.
COMPONENT VERSION RANGE
NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.
The 0.63.x branch of the 2026-08-11 Metabase SQLi pair. See the 0.58 row for the full advisory, the two-series rationale and the fix-train boundary.
COMPONENT VERSION RANGE
NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.
The 1.63.x branch of the 2026-08-11 Metabase SQLi pair. See the 0.58 row for the full advisory, the two-series rationale and the fix-train boundary.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →