CVE-2026-72898 is an actively exploited SQL injection vulnerability in Metabase versions 0.58 and later before branch-specific fixed releases. The flaw is reachable through Metabase’s unauthenticated password-reset API. Request processing permits an attacker-controlled user-id value to persist after failed authentication and reach database query construction. Structured input can be interpreted by HoneySQL as raw SQL rather than a parameterized identifier, enabling arbitrary blind SQL injection into the Metabase application database. Successful exploitation can manipulate the password-reset flow and grant administrator access without valid credentials.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (6 hidden).
This five-file repository contains an operational Python proof of concept and a self-contained Docker laboratory for the claimed CVE-2026-72898 Metabase password-reset SQL injection. metabase_exploit.py is the primary entry point: it POSTs a JSON user-id object with a raw SQL fragment to /api/session/reset_password, ignores the expected HTTP 400 response, and uses response latency as a PostgreSQL pg_sleep-based blind SQL oracle. It randomizes X-Forwarded-For for every request to evade a per-source reset-password throttle where the deployment trusts that header. The extractor supports a check-only mode, custom scalar SQL expressions, configurable delay, and optional disabled TLS verification; its default expression reads the earliest core_user email. The supporting Dockerfile, start.sh, and setup_bg.sh construct a reproducible vulnerable environment using metabase/metabase:v0.62.1 and a localhost PostgreSQL application database. start.sh initializes PostgreSQL, creates the mb role and metabase database, and launches Metabase. setup_bg.sh polls the local session-properties endpoint, retrieves the setup token, and invokes /api/setup to create a randomized-password admin account (admin@lab.local), ensuring the container reaches the login state. The README documents affected and patched version ranges, container startup, extraction examples, and mitigation guidance. No external command-and-control or hard-coded remote attacker infrastructure is present; the only remote target is operator supplied.
Repository contains two files: a README and a single Python exploit script, cve-2026-72898_poc.py. The script is a standalone operational PoC for CVE-2026-72898, an unauthenticated SQL injection in Metabase's password-reset workflow. It is not part of a larger exploit framework. Exploit flow is three-step: (1) GET the target root path / and require HTTP 200, (2) POST crafted JSON to /api/session/reset_password with a malicious user-id.select.raw value containing SQL that inserts a forged admin session row into core_session using a generated UUID and its SHA-256 hash, and (3) send the forged session via X-Metabase-Session to /api/user/current to verify administrator access. If the final request returns HTTP 200 with JSON, the script marks the target vulnerable and prints the forged session ID and admin email. The exploit's main capability is admin takeover without credentials. It does not deploy a shell or arbitrary post-exploitation payload; instead it creates an authenticated Metabase superuser session that can be reused in the browser through the metabase.SESSION cookie. The README documents both single-target and mass-target usage, expected response patterns, and manual browser steps for converting the forged session into full UI access. Code structure is simple: helper functions for colored output, session creation, SQLi body construction, target checking, and CLI parsing. It supports reading targets from a file, configurable timeout, and optional TSV output. The payload is hardcoded and purpose-built for session forgery, making the repository an operational exploit rather than a mere detector.
This repository is a minimal proof-of-concept exploit consisting of a short README and a single Bash script, poc.sh. The script uses curl to send an HTTP POST request to a local web application's password reset endpoint at /api/session/reset_password. The JSON body includes a token, a replacement password, and a nested user-id.raw field containing the SQL injection string "1) OR 1=1 -- ". The apparent goal is to exploit insufficient input sanitization in backend password reset logic, likely causing the reset operation to match unintended users or bypass intended constraints. The exploit is operational but basic: it contains a hardcoded target URL, hardcoded password, and hardcoded injection payload, with no automation, validation, or framework integration. The README provides no meaningful technical guidance.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
118 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical (CVSS 10.0) SQL-injection vulnerability in Metabase that was exploited as a zero-day before patches were released. It was used to compromise Mathspace's self-hosted Metabase instance and resulted in the theft of data affecting more than one million people.
A CVSS 10.0 unauthenticated SQL-injection vulnerability in the password-reset API of self-hosted Metabase installations. It enables arbitrary SQL execution and administrator-account takeover without valid credentials; it was exploited to breach Mathspace’s internal reporting database.
A CVSS 10.0 unauthenticated SQL-injection vulnerability in the password-reset API of self-hosted Metabase installations. It enables arbitrary SQL execution and administrator-account compromise without credentials, and was actively exploited against internet-facing instances, including Mathspace’s reporting system.
A critical, CVSS 10.0 SQL injection vulnerability in Metabase that was exploited as a zero-day in the ShipMonk supply-chain breach, exposing Trezor customer order and personal information.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.