1. Inside the Metabase SQLi: Exploited in the Wild wiz.io | 漏洞 | 2026-08-10 12:30 | 原文 ↗ | #ai-security | #cloud | #sql-injection | #reverse-engineering Wiz 借助 AI 逆向 Metabase SQL 注入 CVE-2026-72898:自 8 月 6 日事件起经 /api/session/reset_password 被在野利用,Framework、Tally、n8n 等受影响;自托管实例需尽快修补。
2. Metabase 密码重置中的严重 SQL 注入漏洞:CVE-2026-72898 bishopfox.com | 漏洞 | 2026-08-06 00:00 | 原文 ↗ | #sql-injection | #exploitation | #vulnerability | #metabase Metabase 密码重置接口存在严重的未认证 SQL 注入(CVE-2026-72898,CVSS 10.0),可对应用数据库执行任意 SQL;官方确认已遭在野利用,建议立即修复。