Skip to content
COOEY

FAIL › dossier

Metabase

VENDOR

Dossier not yet built — the RAG curator builds one for players with ≥2 failure events. The failure history and sentiment below are live.
FAILURE HISTORY · 6
DATEEVENTSEVSUMMARY
2026-08-11 CVE-2026-72898 high Unauthenticated remote SQL injection in Metabase grants attacker full admin access, allowing data theft and configuration changes.
2026-08-11 CVE-2026-72898 high Unauthenticated remote SQL injection in Metabase grants attacker full admin access, allowing data theft and configuration changes.
2024-11-12 CVE-2021-41277 high Metabase's GeoJSON API allows attackers to read arbitrary local files via local file inclusion.
2024-11-12 CVE-2021-41277 high Metabase's GeoJSON API allows attackers to read arbitrary local files via local file inclusion.
2026-07-15 CVE-2026-50148 critical CVE-2026-50148: Metabase is an open-source business intelligence and embedded analytics tool. Fr
2026-07-15 CVE-2026-50148 critical CVE-2026-50148: Metabase is an open-source business intelligence and embedded analytics tool. Fr