Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-13 ยท updated: 2026-08-18 ยท tags: [incident, cisa, kev, metabase, sqli, cve-2026-72898, unauthenticated] ยท confidence: high ยท affected_sectors: [technology, finance, government] ยท au_impact: false

CISA Adds Metabase SQL-Injection Flaw (CVE-2026-72898) to Known Exploited Vulnerabilities

CISA added CVE-2026-72898, an unauthenticated SQL-injection vulnerability in the Metabase analytics/BI platform, to its Known Exploited Vulnerabilities (KEV) catalogue. Exploitation lets an unauthenticated remote attacker inject arbitrary SQL into the Metabase application database, gain administrator access, change application configuration and steal stored credentials for connected databases.

Summary

The KEV addition obliges federal civilian agencies to remediate under BOD 26-04. Metabase is a widely deployed open-source analytics platform; the flaw joins the week's rapid patch-to-exploitation KEV conveyor. Teams using open-source analytics stacks face an administrator-access chain via a BI tool.

Impact

  • Unauthenticated remote code access to the Metabase application database
  • Administrator access and ability to change application configuration
  • Credential theft for databases connected to Metabase
  • Federal civilian agencies must remediate under BOD 26-04

Sector

Global (Macro)

Sources