Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2026-72898 — CVE-2026-72898 | Kitploit
工具/GitHubGitHub/0xblackash/cve-2026-72898
Vulnerability AnalysisExploitationWeb Application ExploitationThreat IntelligenceIncident ResponseDatabase Security
GitHub0xblackash/cve-2026-72898

CVE-2026-72898

CVE-2026-72898

查看仓库
317天前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
内容在请求的语言中不可用。显示英文版本。

🔴 CVE-2026-72898 - Unauthenticated SQL Injection

ChatGPT Image Aug 12, 2026, 02_58_46 PM

Metabase — Unauthenticated SQL Injection → Full Administrator Takeover


CVSS 10.0 Critical Actively Exploited CISA KEV Unauthenticated



📌 Overview

CVE-2026-72898 is a maximum-severity (CVSS 10.0) unauthenticated SQL injection vulnerability in Metabase that allows a remote attacker to inject arbitrary SQL into the application database via the password-reset endpoint.

```
下载工具

Successful exploitation grants full administrator access to the Metabase instance. From there, an attacker can:

  • Modify application configuration
  • Steal stored credentials for connected databases
  • Read any data accessible through those connections
  • Export sensitive data at will

This vulnerability was exploited in the wild as a zero-day against Metabase Cloud and multiple self-hosted customers.



⚡ Key Details

FieldValue
CVE IDCVE-2026-72898
GHSAGHSA-vwf4-m7j8-wcjf
SeverityCritical
CVSS v3.110.0 — AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS v4.010.0
CWECWE-89 — Improper Neutralization of Special Elements used in an SQL Command
Attack VectorNetwork
AuthenticationNone required
User InteractionNone
Exploitation StatusActively exploited in the wild (Zero-day)
CISA KEVListed


🎯 Affected Endpoint

root@kitploit:~
POST /api/session/reset_password
CVE-2026-72898

An unauthenticated attacker can send a crafted request to this endpoint that results in arbitrary SQL execution against the Metabase application database.



📦 Affected Versions

BranchAffected VersionsFixed Version
x.58≥ x.58.0 and < x.58.24x.58.24
x.59≥ x.59.0 and < x.59.21x.59.21
x.60≥ x.60.0 and < x.60.17x.60.17
x.61≥ x.61.0 and < x.61.11x.61.11
x.62≥ x.62.0 and < x.62.9x.62.9
x.63≥ x.63.0 and < x.63.5x.63.5

Versions below 58 are not affected.



🛠️ Remediation

1. Upgrade Immediately (Recommended)

Upgrade to the fixed version corresponding to your major release:

VersionOSS DockerOSS JAREnterprise
63metabase/metabase:v0.63.5Downloadv1.63.5
62metabase/metabase:v0.62.9Downloadv1.62.9
61metabase/metabase:v0.61.11Downloadv1.61.11
60metabase/metabase:v0.60.17Downloadv1.60.17
59metabase/metabase:v0.59.21Downloadv1.59.21
58metabase/metabase:v0.58.24Downloadv1.58.24

2. Temporary Workaround

If you cannot upgrade immediately, block access to the vulnerable endpoint:

root@kitploit:~
/api/session/reset_password


🔍 Detection & Indicators of Compromise

Look for this characteristic attack pattern in your application or ingress logs:

root@kitploit:~
POST /api/session/reset_password   →  400
GET  /api/user/current             →  200

If this sequence appears, your instance is likely compromised.


Post-Upgrade Actions (Highly Recommended)

After upgrading, perform the following:

  1. Invalidate all sessions

    root@kitploit:~
    TRUNCATE TABLE core_session;
    
  2. Review and delete any unrecognized API keys

  3. Audit administrator accounts for unexpected changes

  4. Rotate credentials for all connected databases

  5. Review data warehouse logs for unauthorized access

  6. Examine Metabase activity & query history for anomalies



📚 Official References

  • Metabase Security Advisory (GHSA-vwf4-m7j8-wcjf)
  • Metabase Official Blog Post
  • CVE Record
  • CISA Known Exploited Vulnerabilities Catalog


⚠️ Disclaimer

This document is provided for defensive and informational purposes only.
Always verify information against official vendor advisories.


Upgrade now. Every unpatched instance remains a high-value target.