Metabase SQLi exploit grants attackers total access
Brief
Business intelligence (BI) platform provider Metabase has disclosed a zero-day SQL Injection vulnerability, warning that customers’ sensitive credentials, tokens, API keys, and other data may have been exposed.
The Metabase vulnerability revealed on August 6, designated CVE-2026-72898 , is identified as critical, with a severity score of 10, the highest possible rating. It is present in versions 1. 58 and up.
“You don’t see a perfect 10/10 on CVSS often, but when you do, be worried,” noted David Shipley , CEO of Beauceron Security. SQL injection is “old school and painful, as there’s now working proof of concept exploit code.”
‘Unmitigated, raw’ database access
Metabase is an open-source BI tool that customers can connect to popular databases, including Databricks, MongoDB, Oracle, Snowflake, Amazon, BigQuery, and many others.
