type: cve ยท created: 2026-08-12 ยท updated: 2026-08-12 ยท tags: [cve, kev, sqli, metabase, unauthenticated, exploited-in-the-wild] ยท confidence: high ยท severity: not-rated ยท affected_sectors: [technology, finance, government] ยท au_impact: true
CVE-2026-72898 โ Metabase Unauthenticated SQL Injection
CVE-2026-72898 is an unauthenticated SQL-injection vulnerability in Metabase that grants administrator access. Its in-the-wild exploitation was disclosed over the weekend, and CISA added it to its Known Exploited Vulnerabilities (KEV) catalogue on 2026-08-11 under BOD 26-04.
Vulnerability Details
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-72898 |
| Type | Unauthenticated SQL injection โ administrator access |
| Product | Metabase |
| Access | Unauthenticated |
| KEV status | Added to KEV 2026-08-11 (BOD 26-04) |
| Exploitation status | Exploited in the wild (disclosed over the 2026-08-08/09 weekend) |
Context
CISA added the vulnerability to its KEV Catalogue on 2026-08-11, alongside CVE-2026-20349 (Cisco Secure Firewall ASA/FTD) and CVE-2026-68820 (Windows afd.sys). Federal civilian agencies must prioritise remediation, and CISA urges all organisations to adopt the same risk-based patching posture. Metabase is a widely deployed open-source business-intelligence platform; an unauth path to admin accounts warrants prompt patching.
Related Pages
- Cisa Adds Three Known Exploited Vulnerabilities To Catalog โ CISA KEV addition incident
Sources: raw/digests/Cyber-Digest-2026-08-12