Cybersecurity from Málaga · Networks, lures and threats

CVE-2026-72898

Metabase Metabase

Patch now: it is being exploited

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.