PT-2026-2314 · Metabase · Metabase
Lowimrk
·
Published
2026-01-12
·
Updated
2026-04-10
·
CVE-2026-22805
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Metabase versions prior to 55.13
Metabase versions prior to 56.3
Metabase versions prior to 57.1
Description
Metabase is an open-source data analytics platform. Self-hosted instances allowing user-created subscriptions may be potentially impacted if colocated with other unsecured resources.
Recommendations
Update to Metabase version 55.13 or later.
Update to Metabase version 56.3 or later.
Update to Metabase version 57.1 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Metabase