A security vulnerability has been found in Metabase, a popular tool used to build data dashboards and run database queries for websites and business operations. The flaw is a SQL injection bug, which lets an attacker without any login access to your Metabase instance send unauthorized commands to the database that powers your Metabase setup.
If this flaw is exploited, the attacker can gain full administrator control of your Metabase instance. From there, they could change your Metabase configuration, steal stored login credentials for any external databases you have connected to Metabase, access all data available through those connected databases, and export that data. This puts any sensitive business information, customer data, or database credentials stored in or linked to your Metabase instance at risk of unauthorized access.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-72898