๐ฅ Metabase: Unauthenticated SQL Injection to Admin Takeover Analysis
๐ด CVE-2026-72898 & CVE-2026-72899 ๐ด
๐๏ธ Publish Date: 10 Aug 2026
รLIM rebuilt both, wrote a proof of concept for each, and confirmed it fires on the vulnerable build and stays silent on the patched one.
Metabase has patched CVE-2026-72898 and CVE-2026-72899. Both are unauthenticated SQL injection. Neither one needs a password, a token, or a click.
๐ Full Technical Analysis and PoCs:
CVE-2026-72898: https://t.co/VwJDS7Ulab
CVE-2026-72899: https://t.co/2fOz7msQ0V
Fixed in 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9 and 0.63.5.
--
#Metabase #1dayexploit #ALIM #SQLInjection #RedTeam #OffSec #VulnerabilityResearch #CyberSecurity #InfoSec #AppSec #Exploit
@Jich_ Thanks, glad it is useful.
Both already exist. RSS: https://t.co/fqfZA96FeN
Every write-up, with proper guid and pubDate, and it is auto discoverable from the homepage, so a bot can just point at the domain.
Submissions: https://t.co/EptoK1SF5U
Pick any CVE and request it. No account, no quota. We publish whatever comes back, including the runs where we could not reproduce the claim.
Appreciate you taking the time to look through it.
๐ 1dayexploit is officially live!! ๐๐
Today, weโre excited to open 1dayexploit to the security community.
๐ https://t.co/pOrVDJIyeK
๐ฆ Explore รLIM: https://t.co/L0yo5w50MN
Built for offensive security researchers, 1dayexploit is a platform focused on high-quality technical research, in-depth CVE analysis, root cause investigations, exploit development, PoCs, and practical security insights.
As part of the platform, weโre also introducing รLIM. Our AI-powered research assistant that helps transform CVEs into technical evidence. Rather than simply summarizing vulnerabilities, รLIM analyzes root causes, explains the affected code, assists with exploit development, and helps researchers understand the real-world impact of security issues.
This is just the beginning. Weโre continuously building new research capabilities, AI-driven workflows, and features to help security researchers move faster and dive deeper into vulnerability research.
Weโd love to hear your feedback and suggestions.
โ๏ธ [email protected]
#ALIM #1dayexploit #CyberSecurity #OffensiveSecurity #AppSec #RedTeam #BugBounty #CVE #ExploitDevelopment #VulnerabilityResearch #AI #LLM