A security vulnerability has been identified in Metabase, a popular data analysis and business intelligence tool used by many websites to track and report on performance and operational data. This flaw is a SQL injection issue, which allows an unauthenticated (not logged in) remote attacker to send harmful custom code to the Metabase application's database to gain full administrator access to the Metabase instance.
If an attacker exploits this flaw to get admin control, they could modify your Metabase application's settings, steal saved login credentials for any external databases you have connected to Metabase, view any data those connected databases are permitted to access, and export that data for unauthorized use.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-72898