Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

[KEV] CVE-2026-72898 -- CVSS 0.0 Vulnerability Briefing

[KEV] CVE-2026-72898 | CVSS 0.0 (Low) | Exploit: Operational

What Is It

CVE-2026-72898 is an unauthenticated SQL injection vulnerability in Metabase that affects the Metabase application and its application database.

Technical Detail

An unauthenticated remote attacker can inject arbitrary SQL into the Metabase application database through a vulnerable application input. Successful exploitation can provide administrator-level access to the Metabase instance, constituting an authentication bypass and privilege escalation through manipulation of application data. An attacker with this access may alter application configuration, obtain stored credentials for connected databases, access data available through those connections, and export data.

Exploitation Status

Exploit maturity is assessed as Operational, meaning exploitation capability is usable in real-world attacks rather than remaining limited to a proof of concept. CISA has confirmed active exploitation in the wild. The vulnerability was added to CISA's Known Exploited Vulnerabilities Catalog on August 11, 2026.

Who Is Targeting This

No specific threat actor attribution at this time.

What To Do

Apply the vendor-provided security update for Metabase immediately and prioritize internet-accessible instances. CISA Binding Operational Directive 22-01 requires federal civilian executive branch agencies to patch by September 1, 2026, or apply mitigations. Until patching is complete, restrict public access to Metabase, limit access to trusted networks or identity-aware proxies, review administrative accounts and configuration changes, rotate database credentials stored in Metabase where compromise is suspected, and investigate application-database logs for SQL injection indicators, unexpected administrator account activity, configuration changes, credential access, and unusual data exports.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →