Metabase versions before 0.63.1 fail to enforce data analyst permission checks on glossary API endpoints, allowing any authenticated user to create, modify, and delete glossary entries. Attackers can submit requests to POST, PUT, and DELETE glossary endpoints to tamper with instance-wide business glossary data without proper authorization.
Metrics
Affected Vendors & Products
References
History
Wed, 09 Sep 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 05 Sep 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Metabase versions before 0.63.1 fail to enforce data analyst permission checks on glossary API endpoints, allowing any authenticated user to create, modify, and delete glossary entries. Attackers can submit requests to POST, PUT, and DELETE glossary endpoints to tamper with instance-wide business glossary data without proper authorization. | |
| Title | Metabase before 0.63.1 Missing Function-Level Authorization on the Glossary Management API | |
| First Time appeared |
Metabase
Metabase metabase |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Metabase
Metabase metabase |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-09-05T09:59:06.683Z
Updated: 2026-09-08T17:26:40.648Z
Reserved: 2026-09-05T01:59:20.944Z
Link: CVE-2026-86116
Updated: 2026-09-08T17:26:35.700Z
Status : Received
Published: 2026-09-05T10:16:42.713
Modified: 2026-09-08T18:21:14.853
Link: CVE-2026-86116
No data.