Metabase Metabase: Metabase SQL Injection Vulnerability

  • Thursday, 13th August, 2026
  • 10:05am

If your website uses Metabase (a common tool for building custom data dashboards and reports tied to your site's information), there is a serious security flaw in this software you should be aware of. The vulnerability is a type of input flaw that lets unauthenticated remote attackers send malicious database commands directly to Metabase's internal application database, with no need for a valid account or login to your instance.

If this flaw is exploited, attackers can gain full administrator access to your Metabase setup. From there, they could modify your Metabase instance's configuration, steal saved login credentials for any other databases you have connected Metabase to, access any data those connected databases permit viewing, and export that data for their own use.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-72898

« Back