CVE-2026-72898 | Metabase Pre-Authentication SQL Injection Vulnerability
CVE-2026-72898 is a critical pre-authentication SQL injection in Metabase affecting versions 58.0–63.2, rated CVSS 10.0. Unauthenticated attackers can inject arbitrary SQL via the /api/session/reset_password endpoint to gain full administrator access, steal database credentials, and exfiltrate data. Metabase confirmed active exploitation in the wild as of August 3, 2026, with patches released across all affected branches.