Vulnerability  ·  2026-08-13

Metabase unauthenticated SQL injection leading to full admin takeover — added to CISA KEV

VulnerabilityHigh impactGlobalCVE-2026-72898
CISA added CVE-2026-72898 to the KEV catalog on 2026-08-11, confirming active in-the-wild exploitation of this unauthenticated SQL injection in Metabase.
While Metabase is a general BI tool rather than an AI-native product, it is commonly connected as a data/analytics layer feeding ML pipelines and dashboards on top of AI application data; confirmed active exploitation with admin-level compromise and CISA KEV status makes this a low-blast-radius-but-precise catalogued entry worth tracking for any AI stack that includes Metabase as a reporting layer.
Unauthenticated remote attacker injects arbitrary SQL via the /reset_password database endpoint, gaining administrator access to the Metabase instance and, from there, credentials to any connected databases.
Metabase (on-premises editions, versions prior to patched release)
Upgrade to the patched Metabase release per vendor advisory; federal agencies required to remediate by 2026-08-14 per CISA KEV.
Metabase Security UpdateGitHub Security Advisory GHSA-vwf4-m7j8-wcjf
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →