← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 12, 2026 · 02:40via CSO Online

Metabase SQLi exploit grants attackers total access

Brief

Business intelligence (BI) platform provider Metabase has disclosed a zero-day SQL Injection vulnerability, warning that customers’ sensitive credentials, tokens, API keys, and other data may have been exposed.

The Metabase vulnerability revealed on August 6, designated CVE-2026-72898 , is identified as critical, with a severity score of 10, the highest possible rating. It is present in versions 1. 58 and up.

“You don’t see a perfect 10/10 on CVSS often, but when you do, be worried,” noted David Shipley , CEO of Beauceron Security. SQL injection is “old school and painful, as there’s now working proof of concept exploit code.”

‘Unmitigated, raw’ database access

Metabase is an open-source BI tool that customers can connect to popular databases, including Databricks, MongoDB, Oracle, Snowflake, Amazon, BigQuery, and many others.

Read more on CSO Online