Audit update: CVE-2026-72898 is an unauthenticated SQL injection in Metabase's password-reset endpoint. Metabase confirms active exploitation. The prior RCE wording has been removed because the vendor advisory describes administrator access and downstream data exposure, not code execution.
Impact and attack path
An unauthenticated attacker can inject SQL into the Metabase application database and potentially gain administrator access. That access can enable configuration changes, theft of stored database credentials, and reading or exporting data reachable through connected databases.
⚠ CVE Score — 最高危険度 / CRITICAL
10CRITICALCVE-2026-72898
Affected and fixed branches
- ▸58: >=58.0 and <58.24; update to 58.24 or later
- ▸59: >=59.0 and <59.21; update to 59.21 or later
- ▸60: >=60.0 and <60.17; update to 60.17 or later
- ▸61: >=61.0 and <61.11; update to 61.11 or later
- ▸62: >=62.0 and <62.9; update to 62.9 or later
- ▸63: >=63.0 and <63.5; update to 63.5 or later
Immediate action
- ✓Upgrade to the fixed release for the deployed major branch
- ✓If an immediate upgrade is impossible, temporarily block /api/session/reset_password
- ✓After upgrading, revoke sessions by deleting rows from core_session
- ✓Review API keys and administrators, then rotate credentials for connected databases
- ✓Review Metabase activity, query history, and data-warehouse logs
Primary sources
📦Amazon で関連書籍・ツールを検索
database security incident response
Amazonで探す →(アソシエイトリンク)
