We’re reaching out to share news of a security vulnerability identified in Metabase, a common tool many of our hosting clients use for database analytics and reporting tied to their websites. The flaw is a SQL injection issue, which allows an unauthenticated remote attacker (someone with no existing login access to your Metabase instance) to send harmful commands directly to Metabase’s internal application database. This grants the attacker full administrator access to your Metabase setup. With that level of access, the attacker could alter your Metabase configuration, steal saved login credentials for any external databases you have connected to Metabase, access any data those connected databases are permitted to view, and export that data.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-72898