CVE-2026-22805 affects self-hosted Metabase instances prior to versions 55.13, 56.3, and 57.1, specifically those allowing users to create subscriptions and co-located with other unsecured resources. This vulnerability has a low CVSS score of 2.1, indicating a low severity with high attack complexity and no direct impact on confidentiality, integrity, or availability of the Metabase instance itself. While the vulnerability could potentially impact co-located resources, there is no evidence of active exploitation, no known public exploit code, and it is not listed on the KEV catalog. Despite some community discussion, media coverage is absent.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.55.13CPE matchmatch criteria | cpe:2.3:a:metabase:metabase:*:*:*:*:-:*:*:* | ||
< 1.55.13CPE matchmatch criteria | cpe:2.3:a:metabase:metabase:*:*:*:*:enterprise:*:*:* | ||
>= 0.56.0, < 0.56.3CPE matchmatch criteria | cpe:2.3:a:metabase:metabase:*:*:*:*:-:*:*:* | ||
>= 1.56.0, < 1.56.3CPE matchmatch criteria | cpe:2.3:a:metabase:metabase:*:*:*:*:enterprise:*:*:* | ||
0.57.0CPE matchmatch criteria | cpe:2.3:a:metabase:metabase:0.57.0:beta:*:*:-:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.