Missing Authorization in Metabase - #VU130135
Published: March 27, 2021 / Updated: May 5, 2026
Metabase
Metabase
Description
The vulnerability allows a remote user to modify dashboards without authorization.
The vulnerability exists due to improper access control in the Revision API revert functionality when handling dashboard revision revert requests. A remote user can send a crafted revert request to modify dashboards without authorization.
This issue affects the dashboard revert action.