One free BI tool had a password-reset bug that handed out admin — hackers found it first

A single API endpoint let anyone become an administrator on thousands of self-hosted Metabase servers, and Framework, n8n and Kilo Code already got…

Aliteq
Priya Nair · Software & Systems Editor

The short version

CVE-2026-72898 is a CVSS 10.0 unauthenticated SQL injection in Metabase's password-reset endpoint, granting full admin access.

The short version

Framework, n8n, and Kilo Code have all confirmed real customer data was accessed before the August 6, 2026 public disclosure.

The short version

A public proof-of-concept exploit dropped just four days after disclosure, on August 10.

The short version

Scans found roughly 4,309 potentially vulnerable self-hosted instances out of ~11,000 probable Metabase servers online.

The short version

If you self-host Metabase on any version from 0.58 through 0.63, check your version and patch today.

My honest take

A public proof-of-concept dropped on August 10 — four days after disclosure, and just three days after the first confirmed victim went public. That's not a comfortable head start for anyone still…

Aliteq

Read the full story

One free BI tool had a password-reset bug that handed out admin — hackers found it first

Read the full story on Aliteq