[CIVN-2026-0409] SQL Injection vulnerability in Metabase

By Published On: August 14, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


SQL Injection vulnerability in Metabase


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Systems Affected


Metabase versions


from x.58.0 before x.58.24

from x.59.0 before x.59.21

from x.60.0 before x.60.17

from x.61.0 before x.61.11

from x.62.0 before x.62.9

from x.63.0 before x.63.5

Overview


A vulnerability exists in Metabase which could allow an unauthenticated remote attacker to perform SQL injection in the Metabase application.


Target Audience:

All organizations and individuals using and maintaining Metabase application.


Risk Assessment:

High risk of unauthorized access to the Metabase instance.


Impact Assessment:

High impact on Confidentiality, Integrity and Availability of the system.


Description


Metabase is a business intelligence and data analytics application allowing users to connect to databases for preparing charts, dashboards, reports from the data.


A SQL Injection vulnerability exists in Metabase due to improper validation of user input used for SQL commands. An unauthenticated remote attacker could exploit this vulnerability by injecting arbitrary SQL through the ‘/reset_password’ database endpoint.


Successful exploitation of these vulnerabilities could allow the attacker to gain unauthorized administrator access to the Metabase instance, change the application configuration, read and export data.


Solution


Apply appropriate security updates as mentioned by the vendor:

https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf



Vendor Information


 

https://www.metabase.com/


References


 

https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf


CVE Name

CVE-2026-72898




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmp/IxgACgkQ3jCgcSdc

ys+EGQ/9F27TeR7KYInU1Ne5fxzS8PJRm+TEWT7e4s8f7b8igMWaOiuVD/La5Ehn

Qgqbu0I7MYlyp+L4s//8XiK6qWQyz/Ox7pSjZjx/v4LV9kpQiwCJofpmsZWeoVwr

GltpLjh+A4L0cUBaBSS3Te8qKrReOcBybXvvGfNuH95+Ry5TjruGB91Z2/O4fIQn

GOlNh7OqXmRo4YjExnSoCaXhUMzWEKfIc//gwKqu4LPIg1rEaIlYW+p4KhpvtFqO

HqXG/nOtAEoZaY5MvgtA9bR+I+mHSiYhnEmpd1+d7YGvNN27yPWEeyqnoPBLHbUX

YYptku9bqRRNz4fSsFC8+ERXZ9/AcVrWepBrt3jCAvEDKo8IQepCS2+KwaZsbT8i

KWj75Bbz0OTYOXCVzOfQuTIaiSnTKRPMLY/aaxKcDU9L93nK90hDoj6A7DYNrkIB

HgrhD7/KtyN3idfwNjjSEmW0UX/9FiPaiJUfzM8ugApQZu7K0OGs6o7AnCemExNA

nNpddbGd9DEH+PIeX5pNHt6i9peIIzwRbsd1rBdjxNkYl4cGgykkFH0XZGQJFzRd

u1qnbtd81mWtiZDAPXnMGAluwGMiXIbvhf6/uI3u1KTfuDOjv7wkynftvqkznKHD

HRpBkvm73L86LPDDyl4XOPAlH5+T6oWIrPXaRUxY1xKqpBP2iAs=

=z7GI

—–END PGP SIGNATURE—–


Share this article