The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified a critical SQL injection vulnerability in Metabase, adding it to its Known Exploited Vulnerabilities (KEV) Catalog.
This flaw allows unauthenticated remote attackers to gain administrator-level access to vulnerable instances of the application.
Designated as CVE-2026-72898, this vulnerability was included in the KEV Catalog on August 11, 2026. Federal civilian executive branch agencies must address this issue by August 14, 2026, highlighting the urgency of the risk.
Unauthenticated SQL Injection Risk
CVE-2026-72898 is categorized as an SQL injection vulnerability under CWE-89. According to CISA, this issue enables a remote attacker to inject arbitrary SQL queries into the Metabase application database without requiring prior authentication.
Metabase is a widely used open-source business intelligence and analytics platform that organizations leverage to connect databases, visualize data, and share dashboards.
The application often contains connection details and credentials for underlying data sources, making its compromise potentially harmful beyond just the Metabase server.
If successfully exploited, an attacker could obtain administrator access to a vulnerable Metabase instance. From this vantage point, an intruder could alter application configurations, access stored credentials for connected databases, read data accessible through those database connections, and export sensitive organizational information.
This vulnerability is particularly concerning for Metabase deployments exposed to the internet or instances connected to production databases containing customer records, financial data, internal operational information, or proprietary analytics.
The vulnerability provides a direct route from unauthenticated access to administrative control. Attackers might exploit this access to enumerate configured database connections, harvest secrets stored by the application, and pursue broader data theft.
Potential consequences of this vulnerability include:
- Exposure of database usernames, passwords, tokens, or connection strings stored within Metabase.
- Unauthorized access to data available through configured database integrations.
- Modification of dashboards, user accounts, permissions, and application settings.
- Bulk export of sensitive business intelligence data.
- Use of stolen database credentials for further intrusion activities.
CISA has not yet confirmed whether CVE-2026-72898 has been utilized in ransomware campaigns. However, its addition to the KEV Catalog suggests evidence of exploitation in the wild, highlighting the need for organizations to prioritize it in their patching processes.
Urgent Mitigation Steps
CISA recommends that organizations apply mitigations following vendor instructions and in accordance with Binding Operational Directive 26-04, which prioritizes security updates based on risk.
Organizations using cloud-hosted services should also adhere to applicable BOD 26-04 guidelines or cease using the affected product if effective mitigation cannot be obtained.
Network defenders should promptly identify all Metabase assets, determine if any are externally accessible, and assess their exposure status.
Security teams should prioritize applying vendor-provided fixes, review Metabase administrator accounts and configuration changes, and rotate credentials stored within or accessible through potentially exposed instances.
Organizations are also encouraged to examine logs for suspicious unauthenticated requests, unusual SQL activity, newly created administrator accounts, unexpected data exports, and changes to database connection settings.
If a compromise is suspected, defenders should follow CISA’s forensic triage requirements and retain relevant application, database, authentication, and network logs.
CISA continues to recommend using the KEV Catalog as a key resource for vulnerability management prioritization, especially for flaws known to be actively exploited.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world

