No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 09 Sep 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 05 Sep 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Metabase versions before 0.63.1 fail to enforce data analyst permission checks on glossary API endpoints, allowing any authenticated user to create, modify, and delete glossary entries. Attackers can submit requests to POST, PUT, and DELETE glossary endpoints to tamper with instance-wide business glossary data without proper authorization. | |
| Title | Metabase before 0.63.1 Missing Function-Level Authorization on the Glossary Management API | |
| First Time appeared |
Metabase
Metabase metabase |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Metabase
Metabase metabase |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-08T17:26:40.648Z
Reserved: 2026-09-05T01:59:20.944Z
Link: CVE-2026-86116
Updated: 2026-09-08T17:26:35.700Z
Status : Received
Published: 2026-09-05T10:16:42.713
Modified: 2026-09-08T18:21:14.853
Link: CVE-2026-86116
No data.
OpenCVE Enrichment
Updated: 2026-09-05T11:30:05Z