PT-2026-94085 · Metabase+1 · Metabase

·

CVE-2026-92813

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Metabase versions prior to 0.63.19
Description Improper validation of the unspecified address 0.0.0.0 in custom GeoJSON URLs allows unauthenticated attackers to access loopback services. An attacker can save a malicious GeoJSON entry using the address 0.0.0.0 to trigger requests that return responses from loopback services to unauthenticated callers.
Recommendations Update to version 0.63.19 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92813

Affected Products

Metabase