ZeroDayAlert

CVE-2026-72898: Metabase SQL Injection Vulnerability

Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.

Metabase Metabase Added to KEV 2026-08-11 Federal due 2026-08-14 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

Metabase instances are vulnerable to unauthenticated SQL injection that grants administrator access to the application itself. This affects any organisation running Metabase, whether as a self-hosted deployment or cloud service, that has not applied vendor mitigations. The record does not specify which versions are affected or whether a patch is available.

How to check whether this touches you

  • Inventory all Metabase instances in your estate, including development, staging and production deployments.
  • For each instance, determine whether it is reachable from the public internet or from untrusted networks; check your firewall rules and reverse proxy configurations.
  • Check the Metabase admin panel (Settings > About) or query the running container/process to confirm the installed version; note that version numbers alone do not prove whether a fix has been backported.
  • Test whether unauthenticated access to the application is possible; if you can reach the login page without credentials, the network exposure exists.

What to do

  1. Contact Metabase immediately to obtain patch or mitigation guidance for your specific version; do not assume a public advisory exists yet.
  2. If patching is not immediately available, restrict network access to Metabase to trusted IP ranges and authenticated VPN only; place the instance behind a WAF or reverse proxy that requires authentication.
  3. Enable and retain all application logs, database query logs, and network access logs for at least 90 days; configure alerting on failed and successful login attempts, especially to the admin account.
  4. If your Metabase instance is internet-facing and you cannot patch or restrict access within 72 hours, escalate to your change advisory board and consider taking the instance offline until mitigations are in place.
  5. Review the credentials Metabase holds for connected databases; plan to rotate them after patching is confirmed.

If you find you were exposed

Exploitation of SQL injection typically occurs before public disclosure, so assume your logs may contain evidence of attack attempts weeks or months in the past. Check authentication logs, database query logs, and any audit records for anomalous queries, failed login storms, or admin account creation during periods before today. If log retention is less than 90 days, you may be unable to establish the start of exposure; document this gap and plan longer retention for future incidents.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-72898 is being exploited. It cannot tell you whether Metabase is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →