CVE-2026-72898 Metabase reset_password SQLi exploitation
This rule detects potential SQL injection attacks and anomalous request patterns targeting the '/api/session/reset_password' IIS API endpoint. It identifies common SQL injection payloads within the HTTP request body and flags excessive requests to this endpoint that lack expected JSON structure, which may indicate automated scanning or credential stuffing attempts.
Microsoft Sentinel (KQL)

