← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 12, 2026 · 12:55via CyberPress

CISA Warns of Actively Exploited Metabase Flaw Enabling Admin Account Takeover

Brief

A critical SQL injection vulnerability in Metabase, tracked as CVE-2026-72898, could allow unauthenticated remote attackers to compromise vulnerable instances and obtain administrator-level control.

The flaw, classified under CWE-89, affects the application’s own database layer and creates a path to expose connected data sources, stored credentials, and sensitive business intelligence records.

The issue was added to CISA’s Known Exploited Vulnerabilities catalog on August 11, 2026, with a remediation deadline of August 14. Organizations that operate Metabase, particularly internet-facing deployments, should treat the vulnerability as an immediate patching.

Critical Metabase Flaw

An attacker does not need valid Metabase credentials to exploit CVE-2026-72898.

Read more on CyberPress