Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-72899: Unauthenticated SQL Injection in Metabase
CVE-2026-72899 · published 24 days ago
Summary
An attacker can inject malicious SQL code into a shared Metabase card or dashboard, potentially allowing them to access sensitive data or disrupt the system. This is a serious risk because it can happen without needing a login. To protect your data, ensure that only trusted users can create and share cards and dashboards in Metabase.
What to do
- Update metabase metabase to version x.58.24 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| metabase | metabase | < x.58.24 |
Original advisory text
Metabase SQL injection via public card or dashboard
Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) parameter.
Severity
10.0
Critical
CVSS 3.1: 10.0 (NVD)
CVSS 4.0: 10.0 (NVD)
Exploitation
EPSS <1%
Type
CWE-89SQL Injection
Timeline
Published10 Aug 2026
Updated3 Sep 2026
First seen10 Aug 2026
Monitor software like this
Free during beta