CISA Warns of Actively Exploited Metabase Flaw Enabling Admin Account Takeover
Brief
A critical SQL injection vulnerability in Metabase, tracked as CVE-2026-72898, could allow unauthenticated remote attackers to compromise vulnerable instances and obtain administrator-level control.
The flaw, classified under CWE-89, affects the application’s own database layer and creates a path to expose connected data sources, stored credentials, and sensitive business intelligence records.
The issue was added to CISA’s Known Exploited Vulnerabilities catalog on August 11, 2026, with a remediation deadline of August 14. Organizations that operate Metabase, particularly internet-facing deployments, should treat the vulnerability as an immediate patching.
Critical Metabase Flaw
An attacker does not need valid Metabase credentials to exploit CVE-2026-72898.
