PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72899 Metabase CVE debrief

Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) parameter. The CVE record was published on 2026-08-10T18:18:53.490Z and has not been modified since then. This vulnerability, with a CVSS score of 10, is critical and could lead to unauthorized data access or modification. Metabase users and administrators should be aware of this critical vulnerability and take immediate action to patch their systems. This includes reviewing and updating field-filter (dimension) parameters, monitoring for suspicious SQL activity, and ensuring that all users are aware of the potential risks associated with publicly shared cards or dashboards. Security teams should also review compensating controls for exposed systems while remediation is scheduled and verified, and check relevant monitoring, detection, and logs for exposed assets that need extra review. Additionally, operators and platform administrators should prioritize patching and review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Vulnerability management teams should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed, and asset inventory managers should review affected product deployments in managed environments and assign an owner for follow-up. The potential operational impact of this vulnerability is significant, as it could allow attackers to inject malicious SQL code and compromise the security of Metabase deployments. Therefore, it is essential for all stakeholders to take immediate action to patch their systems and review their security configurations to prevent potential attacks. The source-confidence limits of this vulnerability are based on the CVE description and NVD detail page, which provide reliable information about the vulnerability. However, defenders should verify the affected scope and severity of the vulnerability in their specific environments to ensure that they are adequately protected.

Vendor
Metabase
Product
Unknown
CVSS
CRITICAL 10
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-10
Original CVE updated
2026-08-26
Advisory published
2026-08-10
Advisory updated
2026-08-26

Who should care

Metabase users and administrators should be aware of this critical vulnerability and take immediate action to patch their systems. This includes reviewing and updating field-filter (dimension) parameters, monitoring for suspicious SQL activity, and ensuring that all users are aware of the potential risks associated with publicly shared cards or dashboards. Security teams should also review compensating controls for exposed systems while remediation is scheduled and verified, and check relevant monitoring, detection, and logs for exposed assets that need extra review. Additionally, operators and platform administrators should prioritize patching and review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Vulnerability management teams should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed, and asset inventory managers should review affected product deployments in managed environments and assign an owner for follow-up. This vulnerability may impact various stakeholders, including Metabase users, administrators, security teams, operators, platform administrators, and vulnerability management teams, who should all take necessary precautions to mitigate the vulnerability. The potential operational impact of this vulnerability is significant, as it could allow attackers to inject malicious SQL code and compromise the security of Metabase deployments. Therefore, it is essential for all stakeholders to take immediate action to patch their systems and review their security configurations to prevent potential attacks. The source-confidence limits of this vulnerability are based on the CVE description and NVD detail page, which provide reliable information about the vulnerability. However, defenders should verify the affected scope and severity of the vulnerability in their specific environments to ensure that they are adequately protected. Overall, this vulnerability requires immediate attention from all stakeholders to prevent potential security breaches and ensure the integrity of Metabase deployments. The review context for this vulnerability includes the CVE-

Technical summary

The vulnerability allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) parameter in Metabase. This could lead to unauthorized data access or modification. Metabase users should prioritize patching to prevent potential SQL injection attacks.

Defensive priority

Metabase users should prioritize patching to prevent potential SQL injection attacks.

Recommended defensive actions

  • Patch Metabase to the latest version
  • Review and update field-filter (dimension) parameters
  • Monitor for suspicious SQL activity

Evidence notes

The CVE description indicates that Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) parameter. The CVSS score is 10, indicating a critical vulnerability. Evidence is limited to the CVE description and NVD detail page. Defenders should verify affected Metabase deployments, review field-filter parameters, and monitor for suspicious SQL activity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72899 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72899

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72899 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72899

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/metabase/metabase/security/advisories/GHSA-r8h2-qpfx-mx59

    9119a7d8-5eab-497f-8521-727c672e3725

  • Source reference

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-222-01.json

    9119a7d8-5eab-497f-8521-727c672e3725

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.