A security vulnerability has been identified in Metabase, a popular tool used to view and analyze data from connected databases. This flaw is a SQL injection issue, which means an attacker with no existing account or access to your Metabase instance can exploit it to gain full administrator control of your setup.
If an attacker gains this admin access, they can modify your Metabase's configuration, steal saved login credentials for any databases you have connected to Metabase, read all data those connected databases are able to access, and export that data to external systems.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-72898