CVE-2026-72898: Metabase - Unauthenticated SQL Injection

HoneyLabs honeypots recorded 3 probes matching CVE-2026-72898 from 1 distinct source IP addresses in the last 7 days. Severity is rated critical.

This CVE is on CISA's Known Exploited Vulnerabilities list.

Request paths that identify it

  • /api/session/reset_password

Addresses probing it

Source IPProbesNetworkCountry
194.180.48.2533MEVSPACE sp. z o.o.Germany

Networks it comes from

ASNOrganisationProbesSource IPs
AS201814MEVSPACE sp. z o.o.31

Captured requests

  • /api/session/reset_password

HTTP client fingerprints (JA4H)

  • ge11nn0400_319b7d62f92d

CVE report

CVE report

Open a specific CVE from the CVE tracker.