CVE-2026-72898CISA KEVEPSS p97.2%

CVE-2026-72898Metabase SQL Injection Vulnerability

Metabase / Metabase

Description

Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.

Scoring

CVSS 10.0 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS19.05% probability of exploitation · percentile 97.2% · 2026-10-05T12:00:23Z
Last modified2026-08-12

CISA KEV entry

Added to KEV: 2026-08-11

Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.