Metabase Cloud Customers Were Patched Before They Knew. Self-Hosted Users Had to Do It Themselves.
On August 6 the analytics vendor Metabase said its own cloud service had been attacked through a flaw nobody knew existed. The flaw, now tracked as CVE-2026-72898, scores a perfect 10 on both current CVSS scales. It lets an attacker with no account inject SQL through a public password-reset endpoint and end up as administrator of the instance. What happened next is the part worth reading.
评论
?
参与讨论