PT-2026-2314 · Metabase · Metabase

Lowimrk

·

Published

2026-01-12

·

Updated

2026-04-10

·

CVE-2026-22805

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Metabase versions prior to 55.13 Metabase versions prior to 56.3 Metabase versions prior to 57.1
Description Metabase is an open-source data analytics platform. Self-hosted instances allowing user-created subscriptions may be potentially impacted if colocated with other unsecured resources.
Recommendations Update to Metabase version 55.13 or later. Update to Metabase version 56.3 or later. Update to Metabase version 57.1 or later.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-22805
GHSA-2WGG-7R2P-CMQX

Affected Products

Metabase