A security vulnerability has been identified in Metabase, a common tool used for website data reporting and analysis. This flaw is a type of code injection that allows an unauthenticated (no account required) remote attacker to send unauthorized commands directly to the Metabase application’s database.
If exploited, the attacker will gain full administrator access to the affected Metabase instance. With that access, they can modify the tool’s settings, steal saved login credentials for any databases connected to Metabase, access any data those connected databases are permitted to reach, and export data from the system.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-72898