CVE-2026-72898 is an unauthenticated SQL injection vulnerability in Metabase's password-reset API. Vulnerable processing merges request data with an authentication result, allowing an attacker-controlled user-id value to survive when authentication does not supply one. JSON object keys are converted into Clojure keywords, and a structured user-id containing HoneySQL's :raw construct can reach the t2/select-one query-building operation, bypassing parameterization and enabling arbitrary blind SQL injection into Metabase's application database. Exploitation can provide administrator access. The flaw was introduced in the 58-series authentication refactor, affects unpatched open-source and Enterprise releases in branches 58 through 63, and was exploited as a zero-day against Metabase Cloud.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (6 hidden).
This nine-file repository is a standalone, loopback-restricted exploitation lab, not a framework module or detection-only tool. It attributes a password-reset SQL injection to CVE-2026-72898: an unexpected user-id field allegedly reaches a raw SQL expression in the Metabase application database, enabling temporary administrator-session creation. The CVE attribution and actual injection expression cannot be independently confirmed from the supplied material because the central portion of exp.py is truncated. The visible Python code validates the Compose project, expected image, loopback binding, running service, initial superuser, and synthetic order state. It sends HTTP requests with optional X-Metabase-Session authentication. The visible final stage exports synthetic data, deletes order 105, verifies the deletion, revokes the temporary session, and checks that subsequent authentication returns HTTP 401. Export and deletion are post-authentication actions against a connected analytics database, not direct password-reset injection into that database. Deletion depends on the analytics_reader account's deliberately granted DELETE permission. No reverse shell, external collection endpoint, or arbitrary command-execution payload is visible. compose.yaml defines five services: vulnerable Metabase v0.63.2, patched comparison v0.63.18.3, separate PostgreSQL application databases, and a shared PostgreSQL 16 analytics database. data/01-seed.sh and data/02-seed.sql initialize four customers, five orders, a separate private contact table, and the analytics_reader role. That role receives analytics-schema access but no explicit access to the private schema. start.ps1 creates random credentials and starts selected profiles; verify.ps1 checks HTTP health and synthetic row counts. recover.py restores order 105 through local Docker/database access and removes only recognized export files after containment and header checks. README.md documents setup and comparison, while .gitignore excludes credentials and exports. Six files contain executable or SQL code, covering Python, PowerShell, shell, and SQL. The evidence supports a basic operational lab exploit with fixed follow-on actions, although its success was not tested. The repository URL, analyzed Git reference, and archive size were not supplied; empty metadata strings and size 0 indicate unavailable information.
This five-file repository contains an operational Python proof of concept and a self-contained Docker laboratory for the claimed CVE-2026-72898 Metabase password-reset SQL injection. metabase_exploit.py is the primary entry point: it POSTs a JSON user-id object with a raw SQL fragment to /api/session/reset_password, ignores the expected HTTP 400 response, and uses response latency as a PostgreSQL pg_sleep-based blind SQL oracle. It randomizes X-Forwarded-For for every request to evade a per-source reset-password throttle where the deployment trusts that header. The extractor supports a check-only mode, custom scalar SQL expressions, configurable delay, and optional disabled TLS verification; its default expression reads the earliest core_user email. The supporting Dockerfile, start.sh, and setup_bg.sh construct a reproducible vulnerable environment using metabase/metabase:v0.62.1 and a localhost PostgreSQL application database. start.sh initializes PostgreSQL, creates the mb role and metabase database, and launches Metabase. setup_bg.sh polls the local session-properties endpoint, retrieves the setup token, and invokes /api/setup to create a randomized-password admin account (admin@lab.local), ensuring the container reaches the login state. The README documents affected and patched version ranges, container startup, extraction examples, and mitigation guidance. No external command-and-control or hard-coded remote attacker infrastructure is present; the only remote target is operator supplied.
Repository contains two files: a README and a single Python exploit script, cve-2026-72898_poc.py. The script is a standalone operational PoC for CVE-2026-72898, an unauthenticated SQL injection in Metabase's password-reset workflow. It is not part of a larger exploit framework. Exploit flow is three-step: (1) GET the target root path / and require HTTP 200, (2) POST crafted JSON to /api/session/reset_password with a malicious user-id.select.raw value containing SQL that inserts a forged admin session row into core_session using a generated UUID and its SHA-256 hash, and (3) send the forged session via X-Metabase-Session to /api/user/current to verify administrator access. If the final request returns HTTP 200 with JSON, the script marks the target vulnerable and prints the forged session ID and admin email. The exploit's main capability is admin takeover without credentials. It does not deploy a shell or arbitrary post-exploitation payload; instead it creates an authenticated Metabase superuser session that can be reused in the browser through the metabase.SESSION cookie. The README documents both single-target and mass-target usage, expected response patterns, and manual browser steps for converting the forged session into full UI access. Code structure is simple: helper functions for colored output, session creation, SQLi body construction, target checking, and CLI parsing. It supports reading targets from a file, configurable timeout, and optional TSV output. The payload is hardcoded and purpose-built for session forgery, making the repository an operational exploit rather than a mere detector.
This repository is a minimal proof-of-concept exploit consisting of a short README and a single Bash script, poc.sh. The script uses curl to send an HTTP POST request to a local web application's password reset endpoint at /api/session/reset_password. The JSON body includes a token, a replacement password, and a nested user-id.raw field containing the SQL injection string "1) OR 1=1 -- ". The apparent goal is to exploit insufficient input sanitization in backend password reset logic, likely causing the reset operation to match unintended users or bypass intended constraints. The exploit is operational but basic: it contains a hardcoded target URL, hardcoded password, and hardcoded injection payload, with no automation, validation, or framework integration. The README provides no meaningful technical guidance.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
131 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated SQL injection vulnerability in Metabase's application database that can grant administrator access. Attackers could then steal credentials for connected databases and read or export their data. Exploitation was reported against Metabase's cloud service and AhaSlides, including after patches became available. Versions below 58 are not affected. Operators should install the minimum safe release for their version branch, which is newer than the initial fix.
A critical unauthenticated SQL injection vulnerability in Metabase’s password-reset endpoint, assigned a CVSS score of 10.0. It allows attackers to manipulate the application database, obtain administrator privileges, steal connected-database credentials, and export accessible information. The content attributes Mathspace’s breach affecting 1,079,819 people to exploitation of its self-hosted Metabase installation. Mathspace installed the available patch on August 29, after attackers had downloaded reporting-database information on August 27. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on August 11.
A critical (CVSS 10.0) SQL-injection vulnerability in Metabase that was exploited as a zero-day before patches were released. It was used to compromise Mathspace's self-hosted Metabase instance and resulted in the theft of data affecting more than one million people.
A CVSS 10.0 unauthenticated SQL-injection vulnerability in the password-reset API of self-hosted Metabase installations. It enables arbitrary SQL execution and administrator-account takeover without valid credentials; it was exploited to breach Mathspace’s internal reporting database.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.