A critical security flaw affecting Metabase has been publicly disclosed. Tracked as CVE-2026-72898, this vulnerability involves a SQL injection issue that can allow an unauthenticated remote attacker to inject arbitrary SQL directly into the Metabase application database.

Because of the severity of this issue, it has been added to CISA's Known Exploited Vulnerabilities (KEV) list. Understanding the risks and taking prompt action is essential for anyone running this software in their environment.

What Happened?

The vulnerability allows unauthenticated remote attackers to interact with the Metabase application database via SQL injection. If successfully exploited, this can grant the attacker administrator access to the instance. Once inside with administrative privileges, an attacker gains broad capabilities within the application.

According to security details, these capabilities include:

  • Changing the core application configuration
  • Stealing stored credentials meant for connected databases
  • Reading any data that is accessible through those database connections
  • Exporting sensitive data from the system

Who Should Care?

Small businesses and site owners running Metabase for business intelligence and data visualization need to pay immediate attention to this alert. Because the vulnerability can be exploited remotely without requiring authentication, any publicly accessible instance is potentially at risk.

If your organization relies on Metabase to connect internal databases and analytics environments, an administrative compromise could expose not just the application itself, but every underlying database it connects to. This creates a significant risk of data exposure and operational disruption.

What to Do Now

When dealing with high-severity vulnerabilities like CVE-2026-72898, a structured response is vital:

  1. Verify your exposure: Check your infrastructure to identify all running instances of Metabase, especially those exposed to the public internet.
  2. Review official guidance: Consult the official Korisec CVE tracker page for up-to-date tracking information regarding this advisory.
  3. Apply updates promptly: Check with the vendor for the latest security advisories and apply available patches immediately.
  4. Monitor access logs: Review your system and network access logs for any signs of unauthorized activity or unusual administrative logins.

Keeping your business secure requires continuous visibility into your assets. Run a free check on your external perimeter today at Korisec.