Critical SQL Injection Flaw in Metabase Actively Exploited

AI-generated NewsSnap summary based on source reporting.
Published: 2026-08-25
Category: technology
Source: OffSec
Original source

A critical unauthenticated SQL injection vulnerability, CVE-2026-72898, has been identified in Metabase's password-reset function and is reportedly under active exploitation. This flaw allows attackers to manipulate authentication data, potentially gaining administrator access and compromising sensitive information or connected databases. Organizations utilizing self-hosted Metabase deployments are strongly advised to apply immediate patches to secure their systems.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai