EXPOSURES › CVE-2026-72898
CVE-2026-72898
HIGH ⌖ ON CISA KEV · EXPLOITEDUnauthenticated remote SQL injection in Metabase grants attacker full admin access, allowing data theft and configuration changes.
Metabase's SQL injection flaw lets attackers bypass authentication to execute arbitrary SQL, compromising the entire instance. DIBs must patch immediately and assume any unpatched Metabase deployment is a high-risk data exfiltration vector. This is a classic unpatched vulnerability that was actively exploited in the wild.
Shame score — An unauthenticated SQL injection flaw that grants full administrative control and was actively exploited in the wild represents a severe, avoidable negligence.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.