Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-08-12 ยท updated: 2026-08-12 ยท tags: [cve, kev, sqli, metabase, unauthenticated, exploited-in-the-wild] ยท confidence: high ยท severity: not-rated ยท affected_sectors: [technology, finance, government] ยท au_impact: true

CVE-2026-72898 โ€” Metabase Unauthenticated SQL Injection

CVE-2026-72898 is an unauthenticated SQL-injection vulnerability in Metabase that grants administrator access. Its in-the-wild exploitation was disclosed over the weekend, and CISA added it to its Known Exploited Vulnerabilities (KEV) catalogue on 2026-08-11 under BOD 26-04.

Vulnerability Details

Attribute Detail
CVE CVE-2026-72898
Type Unauthenticated SQL injection โ†’ administrator access
Product Metabase
Access Unauthenticated
KEV status Added to KEV 2026-08-11 (BOD 26-04)
Exploitation status Exploited in the wild (disclosed over the 2026-08-08/09 weekend)

Context

CISA added the vulnerability to its KEV Catalogue on 2026-08-11, alongside CVE-2026-20349 (Cisco Secure Firewall ASA/FTD) and CVE-2026-68820 (Windows afd.sys). Federal civilian agencies must prioritise remediation, and CISA urges all organisations to adopt the same risk-based patching posture. Metabase is a widely deployed open-source business-intelligence platform; an unauth path to admin accounts warrants prompt patching.

Related Pages

Sources: raw/digests/Cyber-Digest-2026-08-12