Impact
Metabase contains a remote, unauthenticated SQL injection flaw in the '/reset_password' endpoint that permits an attacker to inject arbitrary SQL statements. Exploiting this defect enables the attacker to bypass authentication entirely and assume full administrator privileges on the connected Metabase instance. The resulting compromise threatens confidentiality, integrity, and availability of all data and administrative controls within the platform.
Affected Systems
All Metabase products are mentioned in the CVE. No specific version information is provided, so any deployment of Metabase is considered potentially vulnerable until the vendor publishes an update.
Risk and Exploitability
The vulnerability carries a CVSS score of 10 and is listed as not available for EPSS and not in the CISA KEV catalog. The likely attack vector is that attackers can reach the vulnerable endpoint from any network path without authentication, which the description suggests would make exploitation trivial if the database server is exposed online. Based on the description, it is inferred that an attacker can directly access the endpoint without prior authentication and execute arbitrary SQL. Given the severity and ease of exploitation, the risk level is very high and monitoring or mitigation should be implemented immediately.
OpenCVE Enrichment