Skip to content
COOEY

EXPOSURES › CVE-2026-72898

CVE-2026-72898

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-08-11 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-72898 ↗
⌖ EXPLOITED IN THE WILD SHAME 85/100 exploited-in-wildunpatcheddata-breach

Unauthenticated remote SQL injection in Metabase grants attacker full admin access, allowing data theft and configuration changes.

Metabase's SQL injection flaw lets attackers bypass authentication to execute arbitrary SQL, compromising the entire instance. DIBs must patch immediately and assume any unpatched Metabase deployment is a high-risk data exfiltration vector. This is a classic unpatched vulnerability that was actively exploited in the wild.

Shame score — An unauthenticated SQL injection flaw that grants full administrative control and was actively exploited in the wild represents a severe, avoidable negligence.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.