Independent perspective. Actionable security.Know what matters · Reduce exposure

Vulnerability Assurance / Intelligence

Metabase SQL Injection (CVE-2026-72898) Exposure Management

Catalog analysis: CISA added this entry on August 11, 2026. The entry reflects catalog information retrieved on August 31, 2026, not a snapshot archived on the inclusion date. This site’s publication date is shown separately. Check current vendor guidance before acting.

What the vulnerability is

CVE-2026-72898 is a SQL injection vulnerability (CWE-89) affecting Metabase. This flaw allows an unauthenticated remote attacker to inject arbitrary SQL into the application’s internal database. Successful exploitation can grant the attacker administrative access to the Metabase instance.

Once administrative privileges are obtained, the impact extends beyond the application itself. Attackers may modify application configurations, export data, and steal stored credentials for any external databases connected to the Metabase instance, potentially enabling unauthorized access to those downstream data sources.

Exposure and applicability

This vulnerability applies to organizations deploying Metabase instances that are reachable by unauthenticated remote users. The risk is highest for deployments exposed directly to the internet or situated in network segments where untrusted actors can reach the application interface.

Because the vulnerability allows for the theft of stored credentials, the blast radius includes not only the Metabase server but also every database connected to it. Infrastructure owners must identify all assets running Metabase and map the associated data connections to understand the full scope of potential exposure.

Remediation priorities

Our analysis suggests prioritizing remediation based on network visibility and the sensitivity of the connected data sources.

  1. Immediate Patching: The primary corrective action is to apply mitigations according to vendor instructions. This should be prioritized for all internet-facing instances first.
  2. Credential Rotation: Because this vulnerability allows for the theft of stored credentials, patching alone may not be sufficient if a compromise has already occurred. We recommend rotating credentials for all databases connected to Metabase after the application is secured.
  3. Network Isolation: As a compensating control, restricting access to the Metabase interface via VPN or IP allow-lists can reduce the likelihood of unauthenticated remote exploitation while patching is underway.

How to validate remediation

Verification must go beyond confirming a version number. To ensure exposure has been reduced, defenders should:

  • Verify Vendor Compliance: Confirm that all steps outlined in the vendor’s security update have been executed and that the application is running the mitigated version.
  • Audit Administrative Accounts: Review Metabase administrator logs and account lists for any unauthorized accounts created during the window of exposure.
  • Validate Connection Integrity: Check for unusual query patterns or unauthorized access logs on the downstream databases connected to Metabase, which would indicate if stolen credentials were used.

Limits and open questions

A version check alone does not prove that a system is secure; it only proves the software has been updated. Residual risk remains if an attacker gained administrative access prior to patching and established persistence or exfiltrated credentials.

It remains unknown whether this vulnerability has been utilized in ransomware campaigns. Furthermore, while vendor instructions provide the path to remediation, the specific internal database configurations of a given deployment may influence how the SQL injection is executed or mitigated.

Source and editorial note

CVE-2026-72898: Metabase SQL Injection Vulnerability · Source date: August 11, 2026 · Retrieved August 31, 2026.

Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.

Request a Vulnerability Assessment

Turn security intelligence into action.

Discuss your exposure, priorities, and the evidence needed to validate the outcome.

Request a security assessment ↗

Turn security intelligence into action.

Understand exposure, prioritize the response, and define evidence for the outcome.

Request a Security Assessment