← CYBERNETICSINTERN.COMCYBERNETIC INTERN
VulnerabilityNews explainer

A perfect 10: the Metabase flaw that hands over every connected database

CVE-2026-72898 lets an unauthenticated attacker reach admin on Metabase and read every connected database credential. Metabase confirms active exploitation.

Researched and drafted with AI assistance, then reviewed and edited by Shreyas Lipare before publication. Every source below was checked against the original.

CVSS scores rarely reach 10.0. This one does, on both the version 3.1 and version 4.0 scales [2].

CVE-2026-72898 lets a remote, unauthenticated attacker inject SQL through a password-reset endpoint in Metabase and come out the other side with administrator access to the instance [1][2]. Metabase’s own advisory states the company has confirmed active exploitation [1]. CISA added it to the Known Exploited Vulnerabilities catalog on August 11, 2026, with a federal remediation deadline of August 14, 2026 [3].

If you run self-hosted Metabase, this is a today problem.

What happened

Metabase published advisory GHSA-vwf4-m7j8-wcjf on August 6, 2026, describing an SQL injection reachable through an unauthenticated endpoint that leads to administrator access [1]. NVD published the CVE record on August 10, 2026, rating it CVSS 10.0 [2].

The affected versions, from the vendor advisory [1]:

Line Affected Fixed in
x.58 x.58.0 to x.58.22 x.58.24
x.59 x.59.0 to x.59.19 x.59.21
x.60 x.60.0 to x.60.15 x.60.17
x.61 x.61.0 to x.61.9 x.61.11
x.62 x.62.0 to x.62.7 x.62.9
x.63 x.63.0 to x.63.2 x.63.5

Enterprise builds use the same version numbers with a 1. prefix rather than 0. [1].

Metabase’s advice is to upgrade immediately. Where that is not possible in the moment, the advisory offers one temporary measure: block the /api/session/reset_password endpoint [1]. That is a stopgap to buy hours, not a fix.

Why this matters

The instinct with a business intelligence tool is to rank it below the systems it reports on. That instinct is backwards here.

Metabase works by holding connection credentials for every data source it queries: production replicas, warehouses, analytics databases. Administrator access to the Metabase instance is therefore access to that credential set, and to a query interface already wired into all of it. Metabase says as much: a compromised instance allows credential theft, database access and unauthorised data exfiltration [1].

So the impact is not “someone edited our dashboards.” It is that the attacker inherits, in one step, the access your analytics team spent two years configuring, and a legitimate-looking tool through which to use it.

Two properties make this worse than the average critical CVE. It needs no credentials, so there is no phishing step and no account to compromise first. And business intelligence tools are commonly exposed to the internet on purpose, because people need to reach dashboards from home and from phones. The population of internet-facing Metabase instances is not an accident of misconfiguration; it is the intended deployment.

Technical breakdown

The vulnerability is CWE-89, classical SQL injection, in a code path that runs before authentication [2]. Password-reset flows are a recurring source of this class of bug for a structural reason: they must accept input from someone who by definition cannot authenticate yet, and they must look that input up in the database. That places untrusted data into a query at exactly the point where the usual guard (“is this user allowed?”) has not run yet.

The injection targets the application’s own database, the one Metabase uses to store its users, sessions and data source configuration, rather than the warehouses it reports on [2]. That distinction is what makes the escalation to administrator possible.

The route is below. It is described so you can recognise and interrupt it; no payload or request is reproduced.

ATTACK CHAIN
  1. ReconnaissanceIdentifies Metabase instances reachable from the internet, which is a common and intended deployment
    BREAK THE CHAIN HERE
    Put SSO at a reverse proxy in front of the instance, or require VPN. Most teams cannot take a BI tool off the internet outright (it exists to be reached), but forcing authentication at the edge turns an unauthenticated internet attack into a much harder one. Detection: inventory which of your public addresses answer on the Metabase login path.
  2. Initial accessSends crafted input to an unauthenticated password-reset endpoint, placing attacker-controlled SQL into the application database query
    BREAK THE CHAIN HERE
    Upgrade to the fixed release for your line, x.58.24, x.59.21, x.60.17, x.61.11, x.62.9 or x.63.5. If you cannot upgrade within hours, block /api/session/reset_password as the vendor's stopgap and treat it as a countdown. Detection: review access logs for requests to that endpoint, which a healthy instance sees rarely.
  3. Privilege escalationManipulates application database records to obtain administrator rights on the instance
  4. DiscoveryEnumerates configured data sources, saved questions and dashboards to learn what the organisation holds
  5. Credential accessReads the stored connection credentials for every connected database
    BREAK THE CHAIN HERE
    Re-scope every data source connection to a read-only account limited to the schemas that instance actually reports on. This is what decides whether admin access to a dashboard tool is a serious incident or a warehouse breach. Detection: alert on queries through the Metabase service account that match no saved question, and on bulk exports outside working hours.
  6. CollectionQueries the connected warehouses directly through the platform's normal query interface
  7. ExfiltrationExports results using the built-in download and reporting features, producing traffic that resembles ordinary analyst work

Three breaks, and they are worth understanding as a defence-in-depth stack rather than alternatives.

Removing internet exposure severs step one. Most organisations cannot do this outright (the tool exists to be reached), but putting it behind SSO at a reverse proxy, or requiring VPN, changes an unauthenticated internet attack into something much harder.

Upgrading, or blocking the reset endpoint severs step two, and upgrading is the real fix [1].

Scoping database credentials severs step five, and it is the control that determines how bad the day gets. If every connection in Metabase uses a read-only account limited to the specific schemas that instance reports on, then administrator access to Metabase is a serious incident with a bounded blast radius. If those connections use broadly privileged accounts, and in a lot of analytics stacks they do, because it was easier during setup, the attacker gets write access to production data stores.

The final step deserves attention from detection engineers. Once the attacker holds admin and is querying through Metabase, the database-side telemetry shows the Metabase service account doing what the Metabase service account always does. There is no anomalous source address and no unusual client. What is left to detect on is volume, timing and shape: query patterns that do not match any saved dashboard, bulk exports outside working hours, sudden interest in tables no dashboard references.

What defenders should do Monday morning

Immediate: today.

Identify every Metabase instance you run, including ones stood up by data teams outside central IT, and check each against the version table above [1]. Upgrade anything affected. For any instance you cannot upgrade in the next few hours, block /api/session/reset_password as the vendor’s interim measure and treat that as a countdown, not a resolution [1].

Near term: this week.

Work through Metabase’s post-upgrade list, because patching alone does not evict an attacker who was already in: revoke active sessions, audit API keys and administrator accounts for entries you do not recognise, rotate the credentials for every connected database, and review access logs [1]. If an instance was internet-reachable while running a vulnerable version, treat the connected database credentials as exposed rather than waiting for evidence.

Structural: this quarter.

Review what each Metabase data source connection is actually permitted to do. Read-only accounts, scoped to the schemas that instance genuinely needs, convert this class of compromise from a catastrophe into an incident. Put the tool behind SSO at the edge. Add BI and analytics platforms to whatever inventory drives your patching, because they are credential stores that happen to draw charts.

Checklist

  • Find every Metabase instance, including shadow deployments by data teams.
  • Compare each against the affected and fixed version lists in the vendor advisory.
  • Upgrade to the fixed release for your line.
  • If you cannot upgrade today, block /api/session/reset_password as a stopgap.
  • Revoke active sessions after upgrading.
  • Audit administrator accounts and API keys for unfamiliar entries.
  • Rotate credentials for every connected database.
  • Review access logs for the exposure window.
  • Re-scope data source connections to read-only, least-privilege accounts.
  • Put the instance behind SSO or VPN rather than open to the internet.

The lesson underneath the CVE

Patch this one quickly. It is unauthenticated, it is a 10.0, and the vendor says it is being exploited. But the durable question it raises is about privilege, not versions.

Analytics platforms accumulate the most permissive credentials in the organisation, because every new data source is added under time pressure by someone who just needs the connection to work. Nobody revisits it. The result is a single application, often deliberately internet-facing, holding keys to the warehouse.

The version numbers in this post will be irrelevant in a month. The question of what your BI tool’s database accounts are allowed to do will still be sitting there, and it is the one that decides whether the next flaw in this category is an outage or a breach.

FREQUENTLY ASKED

We are on Metabase Cloud rather than self-hosted. Do we need to act?
The vendor advisory's version lists are the authoritative answer for your deployment, and hosted customers are generally patched by the vendor. The urgent population here is self-hosted instances, which nobody upgrades for you. If you are unsure which you are, that uncertainty is itself worth resolving today.
Is patching enough, or do we need to assume compromise?
Metabase's advisory lists post-upgrade steps precisely because patching is not sufficient on its own: revoke sessions, audit API keys and admin accounts, rotate the credentials for connected databases, and review access logs. If your instance was internet-reachable on a vulnerable version, treat those database credentials as exposed.
Why does a flaw in a dashboard tool matter so much?
Because of what the tool holds. Metabase stores connection credentials for every data source it queries. Administrator access to the instance is therefore access to the credentials for your warehouses and production replicas. The breach is not the dashboards; it is everything the dashboards were pointed at.
Could we detect this after the fact?
Partly. Look for unexpected administrator accounts and API keys, and for sessions from unfamiliar addresses, in the application's own logs. The harder problem is that once an attacker has admin, querying connected databases through Metabase looks like normal analyst behaviour, so database-side logs may show nothing obviously wrong. Volume and timing are your best signals.

REFERENCES

  1. [1]SQL injection using an unauthenticated endpoint leading to admin access (GHSA-vwf4-m7j8-wcjf)Metabase · Published August 6, 2026 · Accessed August 14, 2026PRIMARY
  2. [2]CVE-2026-72898 DetailNational Vulnerability Database (NIST) · Published August 10, 2026 · Accessed August 14, 2026PRIMARY
  3. [3]Known Exploited Vulnerabilities Catalog (JSON feed)Cybersecurity and Infrastructure Security Agency (CISA) · Accessed August 14, 2026PRIMARY

BEFORE YOU GO

Was this useful?

Tell me what you'd change, what was unclear, or what you'd want covered next. Replies shape what gets written.

SEND FEEDBACK ↗

The newsletter

Follow along

Notes between posts, and whatever I'm breaking in the lab.

LINKEDIN ↗