A security flaw has been found in Metabase, a data analysis tool many websites use to view and report on stored information. This is a SQL injection vulnerability, which means an unauthenticated remote attacker (someone without a login to your system, accessing it from anywhere on the internet) can send harmful, unauthorized code directly to the Metabase application’s database.
If the flaw is exploited, the attacker gains full administrator access to your Metabase instance. With that level of access, they could change your application’s configuration, steal saved login credentials for any databases connected to your Metabase setup, read all data accessible through those database connections, and export your stored data.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-72898