CVE-2026-92813
- EPSS 0.29%
- Veröffentlicht 16.09.2026 20:32:58
- Zuletzt bearbeitet 22.09.2026 20:25:55
Metabase through 0.63.18 fails to properly validate the unspecified address 0.0.0.0 in custom GeoJSON URLs, allowing unauthenticated attackers to reach loopback services. Attackers can save a malicious GeoJSON entry with 0.0.0.0 and trigger requests ...
CVE-2026-86116
- EPSS 0.24%
- Veröffentlicht 05.09.2026 10:16:42
- Zuletzt bearbeitet 24.09.2026 20:43:32
Metabase versions before 0.63.1 fail to enforce data analyst permission checks on glossary API endpoints, allowing any authenticated user to create, modify, and delete glossary entries. Attackers can submit requests to POST, PUT, and DELETE glossary ...
CVE-2026-72900
- EPSS 0.3%
- Veröffentlicht 10.08.2026 18:18:53
- Zuletzt bearbeitet 26.08.2026 16:52:20
Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database.
- EPSS 0.57%
- Veröffentlicht 10.08.2026 18:18:53
- Zuletzt bearbeitet 26.08.2026 16:52:20
Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) parameter.
- EPSS 10.4%
- Veröffentlicht 10.08.2026 18:18:53
- Zuletzt bearbeitet 12.08.2026 15:18:30
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.
CVE-2026-50147
- EPSS 0.2%
- Veröffentlicht 15.07.2026 15:21:23
- Zuletzt bearbeitet 30.07.2026 14:30:23
Metabase is an open-source business intelligence and embedded analytics tool. From 1.57.0 until 1.57.19.1, 1.58.14.1, 1.59.10, and 1.60.4, an attacker who can configure a Metabase database connection can read arbitrary files from the Metabase server'...
CVE-2026-50148
- EPSS 0.43%
- Veröffentlicht 15.07.2026 15:18:04
- Zuletzt bearbeitet 30.07.2026 14:29:58
Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user with permission to add or edit a database connection can achieve remote ...
CVE-2026-59826
- EPSS 0.54%
- Veröffentlicht 09.07.2026 17:46:36
- Zuletzt bearbeitet 30.07.2026 14:32:02
Metabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2, Metabase did not validate unsafe H2 connection properties on one database-creation code path, allowing an authen...
CVE-2026-59827
- EPSS 0.79%
- Veröffentlicht 09.07.2026 17:43:57
- Zuletzt bearbeitet 13.07.2026 14:31:08
Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection, including the default sample database, deserialize arbitrary Java obje...
CVE-2026-33725
- EPSS 0.76%
- Veröffentlicht 27.03.2026 00:19:39
- Zuletzt bearbeitet 01.04.2026 15:57:59
Metabase is an open source business intelligence and embedded analytics tool. In Metabase Enterprise prior to versions 1.54.22, 1.55.22, 1.56.22, 1.57.16, 1.58.10, and 1.59.4, authenticated admins on Metabase Enterprise Edition can achieve Remote Cod...