Metabase < 0.58.28 Multiple Vulnerabilities

critical Web App Scanning Plugin ID 115416

Synopsis

Metabase < 0.58.28 Multiple Vulnerabilities

Description

According to its self-reported version number, the version of Metabase running on the remote host is prior to 58.28, or 59.x prior to 59.25, or 60.x prior to 60.21, or 61.x prior to 61.15, or 62.x prior to 62.13, or 63.x prior to 63.10. It is, therefore, affected by multiple vulnerabilities :

- Multiple SQL injection issues where a crafted value carried by query parameters and filters, cast options, stored metric and segment definitions, custom column types or schema creation code could reach the database as raw SQL rather than being treated as data.

- A vulnerable version of the HoneySQL SQL generation library. (CVE-2026-61620)

- Incomplete permission checks on content referenced by cards, dashboards, actions and transforms, allowing a user to indirectly reach data or a database they do not otherwise have access to.

- A rate limiting bypass on the login and password reset endpoints by varying a request header, weakening brute-force protection.

- A missing permission revalidation when reverting a card or a dashboard to an earlier version, allowing sensitive settings such as an embedding configuration, a public sharing link, a data source or a collection location to be restored.

- Multiple data sandboxing and connection impersonation bypasses, including the ability for a non-administrator to edit or delete the questions defining a sandbox and thereby elevate their own permissions.

- A loose request body validation on many API endpoints, which acted on unexpected fields.

- Multiple network exposure issues, including a legacy HTTP action execution path allowing server-side request forgery to internal addresses, database SSH tunnels not bound to the loopback interface, and an unauthenticated request able to influence the configured site URL.

- Multiple missing privilege checks on administrative and settings management operations, including public link publishing for a question, the database health-check endpoint, the Settings Manager scope, and a deactivated administrator regaining admin rights on their next single sign-on login.

- A client-side override of the server result row count and download limits.

Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Metabase version 0.58.28 or later.

See Also

https://github.com/metabase/metabase/security/advisories/GHSA-r495-55cx-fjh7

Plugin Details

Severity: Critical

ID: 115416

Type: Version Based

Published: 8/19/2026

Updated: 8/19/2026

Scan Template: basic, full, pci, scan

Risk Information

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: Tenable

CVSS v3

Risk Factor: Critical

Base Score: 10

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVSS Score Source: Tenable

Vulnerability Information

CPE: cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*

Exploit Ease: No known exploits are available

Patch Publication Date: 8/11/2026

Vulnerability Publication Date: 8/11/2026

Reference Information

CVE: CVE-2026-61620