CVE-2026-72898: Metabase SQL Injection Vulnerability
Summary
Metabase has a critical SQL injection vulnerability that allows unauthenticated remote attackers to gain administrator access. This access enables attackers to alter configurations, steal credentials, and exfiltrate data from connected databases.
IFF Assessment
This vulnerability allows attackers to gain administrative access and steal sensitive data, posing a significant threat to defenders.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: August 14, 2026. Known ransomware use: Unknown.
Defender Context
This SQL injection vulnerability in Metabase presents a severe risk, allowing for full administrative control and data theft. Defenders must prioritize patching and apply vendor-provided mitigations immediately, especially for internet-facing instances. The potential for this to be exploited by ransomware, even if currently unknown, warrants heightened vigilance.