Storyline
Critical zero-day vulnerabilities in Metabase allow unauthenticated remote attacks
Metabase has released patches for multiple critical zero-day vulnerabilities, including CVE-2026-72898 and CVE-2026-72899, that allow unauthenticated remote attackers to inject arbitrary SQL commands.
Published 2026-08-10 09:31 UTCUpdated 2026-08-11 02:00 UTC
Current brief openSource links open
This current storyline is open here with summary, metadata, source links, continuity context, and full evidence. Paid is for compare-over-time, alerts, exports, and workflow.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.2 top sources shown
limited source diversity in top sources
Overview
Metabase has released patches for multiple critical zero-day vulnerabilities, including CVE-2026-72898 and CVE-2026-72899, that allow unauthenticated remote attackers to inject arbitrary SQL commands.
Score total
1.05
Momentum 24h
2
Posts
2
Origins
2
Source types
1
Duplicate ratio
0%
Why now
- Active exploitation of these zero-day vulnerabilities has been confirmed, raising immediate risk.
- Metabase has just released official patches that must be applied urgently.
- The critical severity (CVSS 10.0) highlights the potential impact on organizations using Metabase.
Why it matters
- These vulnerabilities allow attackers to gain full admin control over Metabase instances remotely without authentication.
- Exploitation can lead to theft of database credentials and sensitive data exposure.
- Default public sharing settings increase the attack surface, affecting many users.
Continuity snapshot
- Trend status: insufficient_history.
- Continuity stage: emerging_confirmed.
- Current status: open.
- 2 current source-linked posts are attached to this storyline.
All evidence
All evidence
Critical vulnerabilities in Metabase
NCSC-FI - Vulnerabilities · github.com · 2026-08-11 02:00 UTC
Metabase Patches Vulnerability Exploited as Zero-Day
SecurityWeek · securityweek.com · 2026-08-10 11:03 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
- NCSC-FI - Vulnerabilities (1)
- SecurityWeek (1)
Top origin domains (this list)
- github.com (1)
- securityweek.com (1)