Threat Intel
Metabase Unauthenticated SQLi: Detection & Response Checklist (CVE-2026-72898)
Self-hosted Metabase, version x.58.0 through x.63.4, has an unauthenticated SQL injection in POST /api/session/reset_password that writes straight into the application database (the one holding accounts, connections, and settings, not your warehouse). An attacker who reaches that endpoint gets admin of the instance