PT-2026-86387 · Metabase · Metabase
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Metabase versions prior to 0.63.1
Description
Authenticated users can create, modify, and delete glossary entries because the software fails to enforce data analyst permission checks on glossary API endpoints. This allows unauthorized users to tamper with instance-wide business glossary data by submitting requests to the POST, PUT, and DELETE glossary endpoints.
Recommendations
Update to version 0.63.1 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Metabase