Skip to content
KitploitKITPLOIT
FerramentasBlog
Enviar
FerramentasBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

··Feeds·Contato·Privacidade·© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
CVE-2026-72898 — CVE-2026-72898 | Kitploit
Ferramentas/GitHubGitHub/0xblackash/cve-2026-72898
Vulnerability AnalysisExploitationWeb Application ExploitationThreat IntelligenceIncident ResponseDatabase Security
GitHub0xblackash/cve-2026-72898

CVE-2026-72898

CVE-2026-72898

Ver Repositório
3há 17 diasAinda não revisado

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar
Conteúdo não disponível no idioma solicitado. Mostrando versão em inglês.

🔴 CVE-2026-72898 - Unauthenticated SQL Injection

ChatGPT Image Aug 12, 2026, 02_58_46 PM

Metabase — Unauthenticated SQL Injection → Full Administrator Takeover


CVSS 10.0 Critical Actively Exploited CISA KEV Unauthenticated



📌 Overview

```
Baixar ferramenta

CVE-2026-72898 is a maximum-severity (CVSS 10.0) unauthenticated SQL injection vulnerability in Metabase that allows a remote attacker to inject arbitrary SQL into the application database via the password-reset endpoint.

Successful exploitation grants full administrator access to the Metabase instance. From there, an attacker can:

  • Modify application configuration
  • Steal stored credentials for connected databases
  • Read any data accessible through those connections
  • Export sensitive data at will

This vulnerability was exploited in the wild as a zero-day against Metabase Cloud and multiple self-hosted customers.



⚡ Key Details

FieldValue
CVE IDCVE-2026-72898
GHSAGHSA-vwf4-m7j8-wcjf
SeverityCritical
CVSS v3.110.0 — AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS v4.010.0
CWECWE-89 — Improper Neutralization of Special Elements used in an SQL Command
Attack VectorNetwork
AuthenticationNone required
User InteractionNone
Exploitation StatusActively exploited in the wild (Zero-day)
CISA KEVListed


🎯 Affected Endpoint

root@kitploit:~
POST /api/session/reset_password
CVE-2026-72898

An unauthenticated attacker can send a crafted request to this endpoint that results in arbitrary SQL execution against the Metabase application database.



📦 Affected Versions

BranchAffected VersionsFixed Version
x.58≥ x.58.0 and < x.58.24x.58.24
x.59≥ x.59.0 and < x.59.21x.59.21
x.60≥ x.60.0 and < x.60.17x.60.17
x.61≥ x.61.0 and < x.61.11x.61.11
x.62≥ x.62.0 and < x.62.9x.62.9
x.63≥ x.63.0 and < x.63.5x.63.5

Versions below 58 are not affected.



🛠️ Remediation

1. Upgrade Immediately (Recommended)

Upgrade to the fixed version corresponding to your major release:

VersionOSS DockerOSS JAREnterprise
63metabase/metabase:v0.63.5Downloadv1.63.5
62metabase/metabase:v0.62.9Downloadv1.62.9
61metabase/metabase:v0.61.11Downloadv1.61.11
60metabase/metabase:v0.60.17Downloadv1.60.17
59metabase/metabase:v0.59.21Downloadv1.59.21
58metabase/metabase:v0.58.24Downloadv1.58.24

2. Temporary Workaround

If you cannot upgrade immediately, block access to the vulnerable endpoint:

root@kitploit:~
/api/session/reset_password


🔍 Detection & Indicators of Compromise

Look for this characteristic attack pattern in your application or ingress logs:

root@kitploit:~
POST /api/session/reset_password   →  400
GET  /api/user/current             →  200

If this sequence appears, your instance is likely compromised.


Post-Upgrade Actions (Highly Recommended)

After upgrading, perform the following:

  1. Invalidate all sessions

    root@kitploit:~
    TRUNCATE TABLE core_session;
    
  2. Review and delete any unrecognized API keys

  3. Audit administrator accounts for unexpected changes

  4. Rotate credentials for all connected databases

  5. Review data warehouse logs for unauthorized access

  6. Examine Metabase activity & query history for anomalies



📚 Official References

  • Metabase Security Advisory (GHSA-vwf4-m7j8-wcjf)
  • Metabase Official Blog Post
  • CVE Record
  • CISA Known Exploited Vulnerabilities Catalog


⚠️ Disclaimer

This document is provided for defensive and informational purposes only.
Always verify information against official vendor advisories.


Upgrade now. Every unpatched instance remains a high-value target.