Our takeCISA added CVE-2026-72898 to KEV: unauthenticated SQL injection in Metabase that yields admin access, credential theft, and data exfil. Patch immediately if you run Metabase yourself.Cyber Resilience desk
Sources (4)
- cisa_kev · cisa_kev
- cisa_advisories · cisa_advisories
- bleeping · bleeping
- hackernews · hackernews
What this means for you — Security leader:CISA added CVE-2026-72898 (Metabase SQL injection) to KEV: actively exploited. Patch to 0.51.5 or later immediately if you self-host Metabase; cloud-hosted instances are not affected.
What this means for you — Lean IT orgs:If you run your own Metabase server, update it to version 0.51.5 or newer right away. Most teams using the hosted Metabase service can ignore this one.
What this means for you — MSP:Check client inventories for self-hosted Metabase instances and patch CVE-2026-72898 to 0.51.5+ immediately; cloud Metabase tenants are unaffected.
What this means for you — Researcher:CISA added CVE-2026-72898 to KEV: unauthenticated SQL injection in Metabase allowing admin access and data exfiltration. Confirmed active exploitation.