[KEV] CVE-2026-72898 -- CVSS 0.0 Vulnerability Briefing
[KEV] CVE-2026-72898 | CVSS 0.0 (Low) | Exploit: Operational
What Is It
CVE-2026-72898 is an unauthenticated SQL injection vulnerability in Metabase that affects the Metabase application and its application database.
Technical Detail
An unauthenticated remote attacker can inject arbitrary SQL into the Metabase application database through a vulnerable application input. Successful exploitation can provide administrator-level access to the Metabase instance, constituting an authentication bypass and privilege escalation through manipulation of application data. An attacker with this access may alter application configuration, obtain stored credentials for connected databases, access data available through those connections, and export data.
Exploitation Status
Exploit maturity is assessed as Operational, meaning exploitation capability is usable in real-world attacks rather than remaining limited to a proof of concept. CISA has confirmed active exploitation in the wild. The vulnerability was added to CISA's Known Exploited Vulnerabilities Catalog on August 11, 2026.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Apply the vendor-provided security update for Metabase immediately and prioritize internet-accessible instances. CISA Binding Operational Directive 22-01 requires federal civilian executive branch agencies to patch by September 1, 2026, or apply mitigations. Until patching is complete, restrict public access to Metabase, limit access to trusted networks or identity-aware proxies, review administrative accounts and configuration changes, rotate database credentials stored in Metabase where compromise is suspected, and investigate application-database logs for SQL injection indicators, unexpected administrator account activity, configuration changes, credential access, and unusual data exports.