A security flaw has been found in Metabase, a data analytics tool that many websites use to organize and review their data. This vulnerability is a type of SQL injection, which allows an unauthorized person to send malicious commands directly to the Metabase application's database without needing a valid account or login credentials.
If this flaw is exploited, an attacker can gain full administrator access to the affected Metabase instance. With that access, they could change the application's configuration, steal saved login details for any external databases connected to Metabase, read all data accessible through those connected databases, and export that data.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-72898