A critical zero-day SQL Injection vulnerability, designated as CVE-2026-72898, has been disclosed by Metabase, a business intelligence platform provider, affecting versions 1.58 and later. This vulnerability has the highest possible severity score of 10, indicating a high level of risk. The flaw allows attackers to gain total access to sensitive credentials, tokens, API keys, and other data. The vulnerability was revealed on August 6, and its exploitation status is currently being discussed, particularly in relation to Meta. Experts warn that a perfect 10/10 CVSS score is rare and warrants concern1. The presence of this vulnerability in Metabase's platform poses a significant threat to customers' data security. So what matters to practitioners is that they must prioritize patching or monitoring their systems to prevent potential exploitation of this critical vulnerability.
Metabase SQLi exploit grants attackers total access
⚠️ Critical Alert
Why This Matters
CVE-2026-72898 is in active discussion involving Meta — exploitation status determines whether this is patch-now or monitor.
References
- CSO Online. (2026, August 12). Metabase SQLi exploit grants attackers total access. *CSO Online*. https://www.csoonline.com/article/4208307/metabase-sqli-exploit-grants-attackers-total-access.html
Original Source
CSO Online
Read original →