Metabase Metabase: Metabase SQL Injection Vulnerability

  • Friday, 14th August, 2026
  • 16:05pm

A security vulnerability has been found in Metabase, a data analytics tool many website owners use to track, analyze, and report on their site's data. This flaw is a database security issue that allows unauthenticated remote attackers (people who do not have your Metabase login credentials) to inject harmful custom database commands into your Metabase instance.

If this vulnerability is exploited, attackers can gain full administrator access to your Metabase setup. With that access, they could change your Metabase's configuration, steal saved login credentials for any external databases you have connected to Metabase, read any data those connected databases are permitted to access, and export that data for unauthorized use.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-72898

« Back