Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2026-72898] Inside the Metabase SQLi: Exploited in the Wild

Summary

Wiz reverse-engineers CVE-2026-72898, the Metabase SQLi exploited in the wild via /api/session/reset_password since the Aug 6 incident; about 13% of cloud environments self-host Metabase.
Published
Collected

original ↗

Related coverage

back