Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 05 Sep 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Metabase versions before 0.63.1 fail to enforce data analyst permission checks on glossary API endpoints, allowing any authenticated user to create, modify, and delete glossary entries. Attackers can submit requests to POST, PUT, and DELETE glossary endpoints to tamper with instance-wide business glossary data without proper authorization. | |
| Title | Metabase before 0.63.1 Missing Function-Level Authorization on the Glossary Management API | |
| First Time appeared |
Metabase
Metabase metabase |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Metabase
Metabase metabase |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-05T09:59:06.683Z
Reserved: 2026-09-05T01:59:20.944Z
Link: CVE-2026-86116
No data.
Status : Received
Published: 2026-09-05T10:16:42.713
Modified: 2026-09-05T10:16:42.713
Link: CVE-2026-86116
No data.
OpenCVE Enrichment
No data.