[CVE-2026-72898] Inside the Metabase SQLi: Exploited in the Wild
wiz.io | vulnerability | CVE-2026-72898 | #ai-security | #cloud | #sql-injection | #reverse-engineering | #metabase | #exploited-in-the-wild | #cve-2026-72898 | #wiz
Summary
Wiz reverse-engineers CVE-2026-72898, the Metabase SQLi exploited in the wild via /api/session/reset_password since the Aug 6 incident; about 13% of cloud environments self-host Metabase.
- Published
- Collected
Skip to content