Metabase Cloud Customers Were Patched Before They Knew. Self-Hosted Users Had to Do It Themselves.

On August 6 the analytics vendor Metabase said its own cloud service had been attacked through a flaw nobody knew existed. The flaw, now tracked as CVE-2026-72898, scores a perfect 10 on both current CVSS scales. It lets an attacker with no account inject SQL through a public password-reset endpoint and end up as administrator of the instance. What happened next is the part worth reading.

Source

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论