What happened
CISA added CVE-2026-72898 to the KEV catalog on 2026-08-11, confirming active in-the-wild exploitation of this unauthenticated SQL injection in Metabase.
Why it matters
While Metabase is a general BI tool rather than an AI-native product, it is commonly connected as a data/analytics layer feeding ML pipelines and dashboards on top of AI application data; confirmed active exploitation with admin-level compromise and CISA KEV status makes this a low-blast-radius-but-precise catalogued entry worth tracking for any AI stack that includes Metabase as a reporting layer.
Attack vector
Unauthenticated remote attacker injects arbitrary SQL via the /reset_password database endpoint, gaining administrator access to the Metabase instance and, from there, credentials to any connected databases.
Affected systems
Metabase (on-premises editions, versions prior to patched release)
Mitigation
Upgrade to the patched Metabase release per vendor advisory; federal agencies required to remediate by 2026-08-14 per CISA KEV.