ESC
Type to search CVEs in real-time
Enter open Esc close Ctrl K toggle

CVE-2026-72898

CRITICAL Export PDF

Metabase Metabase Vulnerability

Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.

CVSS Score
9.8
CRITICAL
Published
11 Aug 2026 00:00
Modified
N/A
Vendor
Metabase
Product
Metabase
Source
CIRCL

Affected Versions

Fix Vendor Patch / Mitigation Available

Weaknesses (CWE)

CWE-89

Affected Systems

Metabase
Metabase
Metabase
Metabase

KEV Status

Known Exploited Vulnerability