A security vulnerability has been found in Metabase, a popular data analysis and reporting tool used by many websites to manage and visualize their data. This flaw is a SQL injection issue, which allows unauthenticated remote attackers (people who do not have login access to your systems) to inject harmful, custom database commands directly into your Metabase application database.
If this vulnerability is exploited, an attacker could gain full administrator control of your Metabase instance. With that access, they could change the tool's configuration, steal saved login credentials for any databases your Metabase is connected to, read any data accessible through those connections, and export that data for their own use.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-72898