CVE-2026-86116
largeMissing Authorization in Metabase Glossary API Allows Data Tampering by Any User
Metabase versions before 0.63.1 fail to enforce data analyst permission checks on the glossary API endpoints, a missing-authorization flaw (CWE-862). Any authenticated user, regardless of assigned permissions, can send POST, PUT, and DELETE requests to the glossary endpoints. This lets the user create, modify, or delete instance-wide business glossary entries without proper authorization, corrupting shared business terminology (high integrity impact, no confidentiality impact; CVSS 4.0 score 7.1, High). All Metabase deployments prior to 0.63.1 that grant access to non-admin users are affected. No public proof-of-concept or in-the-wild exploitation is known, it is not listed in CISA KEV, and EPSS estimates only a 0.2% probability of exploitation within 30 days.
What to do: Upgrade to Metabase 0.63.1 or later. As an interim mitigation, restrict access to the glossary API endpoints at a reverse proxy so only authorized analysts or admins can issue POST, PUT, and DELETE requests, and review audit logs for glossary changes made by non-analyst accounts.
| Metabase | all versions before 0.63.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Metabase versions before 0.63.1 fail to enforce data analyst permission checks on glossary API endpoints, allowing any authenticated user to create, modify, and delete glossary entries. Attackers can submit requests to POST, PUT, and DELETE glossary endpoints to tamper with instance-wide business glossary data without proper authorization.
- Weakness
- CWE-862
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.