A security vulnerability has been discovered in Metabase, a popular tool many websites use to query, visualize, and report on their data. This flaw allows unauthenticated (meaning no login is required) remote attackers to send malicious, unauthorized commands directly to the database that powers your Metabase instance.
If exploited, this vulnerability lets attackers gain full administrative access to your Metabase setup. With that control, they could change your instance's configuration, steal saved login credentials for any external databases you have connected to Metabase, access all data available through those connected databases, and export that data without your permission.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-72898