Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2026-72898 — CVE-2026-72898 | Kitploit
도구/GitHubGitHub/0xblackash/cve-2026-72898
Vulnerability AnalysisExploitationWeb Application ExploitationThreat IntelligenceIncident ResponseDatabase Security
GitHub0xblackash/cve-2026-72898

CVE-2026-72898

CVE-2026-72898

저장소 보기
317일 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

🔴 CVE-2026-72898 - Unauthenticated SQL Injection

ChatGPT Image Aug 12, 2026, 02_58_46 PM

Metabase — Unauthenticated SQL Injection → Full Administrator Takeover


CVSS 10.0 Critical Actively Exploited CISA KEV Unauthenticated



📌 Overview

CVE-2026-72898 is a maximum-severity (CVSS 10.0) unauthenticated SQL injection vulnerability in Metabase that allows a remote attacker to inject arbitrary SQL into the application database via the password-reset endpoint.

```
도구 다운로드

Successful exploitation grants full administrator access to the Metabase instance. From there, an attacker can:

  • Modify application configuration
  • Steal stored credentials for connected databases
  • Read any data accessible through those connections
  • Export sensitive data at will

This vulnerability was exploited in the wild as a zero-day against Metabase Cloud and multiple self-hosted customers.



⚡ Key Details

FieldValue
CVE IDCVE-2026-72898
GHSAGHSA-vwf4-m7j8-wcjf
SeverityCritical
CVSS v3.110.0 — AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS v4.010.0
CWECWE-89 — Improper Neutralization of Special Elements used in an SQL Command
Attack VectorNetwork
AuthenticationNone required
User InteractionNone
Exploitation StatusActively exploited in the wild (Zero-day)
CISA KEVListed


🎯 Affected Endpoint

root@kitploit:~
POST /api/session/reset_password
CVE-2026-72898

An unauthenticated attacker can send a crafted request to this endpoint that results in arbitrary SQL execution against the Metabase application database.



📦 Affected Versions

BranchAffected VersionsFixed Version
x.58≥ x.58.0 and < x.58.24x.58.24
x.59≥ x.59.0 and < x.59.21x.59.21
x.60≥ x.60.0 and < x.60.17x.60.17
x.61≥ x.61.0 and < x.61.11x.61.11
x.62≥ x.62.0 and < x.62.9x.62.9
x.63≥ x.63.0 and < x.63.5x.63.5

Versions below 58 are not affected.



🛠️ Remediation

1. Upgrade Immediately (Recommended)

Upgrade to the fixed version corresponding to your major release:

VersionOSS DockerOSS JAREnterprise
63metabase/metabase:v0.63.5Downloadv1.63.5
62metabase/metabase:v0.62.9Downloadv1.62.9
61metabase/metabase:v0.61.11Downloadv1.61.11
60metabase/metabase:v0.60.17Downloadv1.60.17
59metabase/metabase:v0.59.21Downloadv1.59.21
58metabase/metabase:v0.58.24Downloadv1.58.24

2. Temporary Workaround

If you cannot upgrade immediately, block access to the vulnerable endpoint:

root@kitploit:~
/api/session/reset_password


🔍 Detection & Indicators of Compromise

Look for this characteristic attack pattern in your application or ingress logs:

root@kitploit:~
POST /api/session/reset_password   →  400
GET  /api/user/current             →  200

If this sequence appears, your instance is likely compromised.


Post-Upgrade Actions (Highly Recommended)

After upgrading, perform the following:

  1. Invalidate all sessions

    root@kitploit:~
    TRUNCATE TABLE core_session;
    
  2. Review and delete any unrecognized API keys

  3. Audit administrator accounts for unexpected changes

  4. Rotate credentials for all connected databases

  5. Review data warehouse logs for unauthorized access

  6. Examine Metabase activity & query history for anomalies



📚 Official References

  • Metabase Security Advisory (GHSA-vwf4-m7j8-wcjf)
  • Metabase Official Blog Post
  • CVE Record
  • CISA Known Exploited Vulnerabilities Catalog


⚠️ Disclaimer

This document is provided for defensive and informational purposes only.
Always verify information against official vendor advisories.


Upgrade now. Every unpatched instance remains a high-value target.