Missing Critical Step in Authentication in Metabase - CVE-2022-39360
Published: October 24, 2022 / Updated: May 5, 2026
Metabase
Metabase
Description
The vulnerability allows a remote user to bypass single sign-on authentication.
The vulnerability exists due to missing critical step in authentication in the password reset functionality when handling password reset requests for SSO users. A remote user can initiate a password reset for an SSO account to bypass single sign-on authentication.