What is CVE-2026-72898?
A SQL Injection vulnerability has been identified in the Metabase analytics platform that allows an unauthenticated remote attacker to inject arbitrary SQL into the application database. This can lead to administrator access, enabling the attacker to change configuration and steal stored data. Users are advised to immediately update their Metabase instances to the latest patched version.
Azərbaycanca: Metabase analitik platformasında autentifikasiya olunmamış uzaqdan hücumçuya tətbiq verilənlər bazasına ixtiyari SQL kodu yeritməyə imkan verən SQL Injection zəifliyi aşkarlanıb. Bu, administrator girişi əldə edərək konfiqurasiyanı dəyişməyə və saxlanılan məlumatları oğurlamağa səbəb ola bilər. İstifadəçilərə dərhal Metabase instansiyalarını ən son təhlükəsizlik yeniləməsinə keçirmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ1
Why does the CVE-2026-72898 vulnerability pose a critical risk to Metabase users?
Because this SQL Injection vulnerability allows an unauthenticated remote attacker to inject arbitrary SQL into the application database, gaining administrator access. This enables the attacker to change configuration and steal stored data.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.