← Back

CVE-2026-22805

nvd nist
Published: Jan 12, 2026Modified: Jun 17, 2026

JSON object

Loading...
2.1
Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: security-advisories@github.com (Secondary)

Description

Metabase is an open-source data analytics platform. Prior to 55.13, 56.3, and 57.1, self-hosted Metabase instances that allow users to create subscriptions could be potentially impacted if their Metabase is colocated with other unsecured resources. This vulnerability is fixed in 55.13, 56.3, and 57.1.

Affected (6)

Products: Metabase: Metabase
1 product
Metabase
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Metabase
Before 0.55.13
From 0.56.0 to 0.56.3
Before 1.55.13
From 1.56.0 to 1.56.3
Version 0.57.0 beta
Version 1.57.0 beta

References (1)

Source: security-advisories@github.com
MitigationVendor Advisory

Timeline

No history available yet.