漏洞  ·  2026-08-13

Metabase 未经身份验证的 SQL 注入导致完整管理接管 — 添加到 CISA KEV

漏洞High 影响GlobalCVE-2026-72898
CISA 于 2026 年 8 月 11 日将 CVE-2026-72898 添加到 KEV 目录,确认积极利用 Metabase 中这个未经身份验证的 SQL 注入的真实情况。
虽然 Metabase 是一般 BI 工具而不是 AI 原生产品,但它通常作为数据/分析层连接,为 AI 应用程序数据之上的 ML 管道和仪表板提供信息;确认积极利用和管理员级别妥协,以及 CISA KEV 状态使其成为低冲击半径但精确编目的条目,值得
Unauthenticated remote attacker injects arbitrary SQL via the /reset_password database endpoint, gaining administrator access to the Metabase instance and, from there, credentials to any connected databases.
Metabase (on-premises editions, versions prior to patched release)
Upgrade to the patched Metabase release per vendor advisory; federal agencies required to remediate by 2026-08-14 per CISA KEV.
Metabase Security UpdateGitHub Security Advisory GHSA-vwf4-m7j8-wcjf
在实时动态中查看 浏览更多 AI 安全与治理相关发现 — 每日清晨更新。
打开动态 →