A popular data analysis tool called Metabase has a critical security vulnerability. This flaw, known as a SQL injection issue, can be exploited by remote attackers who do not need any existing login credentials to access your Metabase instance.
If you run Metabase on your hosting account, a successful attack would give the attacker full administrator control of your Metabase setup. From there, they could change your Metabase configuration, steal saved login details for any databases you have connected to the tool, access all data available through those connected databases, and export that data.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-72898