{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2026-72898",
  "revision": 1,
  "title": "Metabase — unauthenticated SQL injection to admin takeover",
  "summary": "A SQL injection flaw in Metabase's password-reset endpoint lets anyone on the network, with no login, run arbitrary SQL against the application database and take over the instance as an administrator, exposing stored database credentials and all connected data.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 10,
    "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
    "version": "4.0"
  },
  "epss": 0.94217,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2026-08-11",
    "prerequisites": "Network access to the Metabase web interface; no account or user interaction needed."
  },
  "remediation": {
    "patch_available": true
  },
  "mitre_attack": [
    "T1190"
  ],
  "kill_chain": "initial_access",
  "recommended_action": "Update Metabase to the vendor-patched release now; restrict internet exposure until patched, then rotate connected-database credentials and review admin and export activity.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-72898",
      "retrieved_at": "2026-09-22T06:10:25.213Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-22T06:10:25.213Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2026-72898",
      "retrieved_at": "2026-09-22T06:10:25.213Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-72898",
      "retrieved_at": "2026-09-22T06:10:25.213Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-72898",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf"
    },
    {
      "type": "vendor_advisory",
      "url": "https://www.metabase.com/blog/security-update"
    },
    {
      "type": "writeup",
      "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-222-01.json"
    }
  ],
  "published_at": "2026-08-10T18:18:53.300Z",
  "issued_at": "2026-09-22T06:10:25.213Z",
  "tags": [
    "metabase",
    "sql-injection",
    "kev",
    "unauthenticated",
    "business-intelligence"
  ]
}
