A security vulnerability has been found in Metabase, a popular tool many websites use to connect to their databases, run data queries, and generate visual reports. This flaw allows attackers who do not have any login access to your Metabase instance to run unauthorized, malicious commands on the database that powers the application.
If this vulnerability is exploited, the attacker can gain full administrator access to your Metabase instance. This would let them change your application’s settings, steal saved login credentials for all the databases your Metabase instance is connected to, read any data those connected databases are able to access, and export that data for their own use.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-72898