FAIL › dossier
Metabase
VENDORDossier not yet built — the RAG curator builds one for players with ≥2 failure events. The failure history and sentiment below are live.
FAILURE HISTORY · 6
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-08-11 | CVE-2026-72898 | high | Unauthenticated remote SQL injection in Metabase grants attacker full admin access, allowing data theft and configuration changes. |
| 2026-08-11 | CVE-2026-72898 | high | Unauthenticated remote SQL injection in Metabase grants attacker full admin access, allowing data theft and configuration changes. |
| 2024-11-12 | CVE-2021-41277 | high | Metabase's GeoJSON API allows attackers to read arbitrary local files via local file inclusion. |
| 2024-11-12 | CVE-2021-41277 | high | Metabase's GeoJSON API allows attackers to read arbitrary local files via local file inclusion. |
| 2026-07-15 | CVE-2026-50148 | critical | CVE-2026-50148: Metabase is an open-source business intelligence and embedded analytics tool. Fr |
| 2026-07-15 | CVE-2026-50148 | critical | CVE-2026-50148: Metabase is an open-source business intelligence and embedded analytics tool. Fr |