PatchSiren cyber security CVE debrief
CVE-2026-72899 Metabase CVE debrief
Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) parameter. The CVE record was published on 2026-08-10T18:18:53.490Z and has not been modified since then. This vulnerability, with a CVSS score of 10, is critical and could lead to unauthorized data access or modification. Metabase users and administrators should be aware of this critical vulnerability and take immediate action to patch their systems. This includes reviewing and updating field-filter (dimension) parameters, monitoring for suspicious SQL activity, and ensuring that all users are aware of the potential risks associated with publicly shared cards or dashboards. Security teams should also review compensating controls for exposed systems while remediation is scheduled and verified, and check relevant monitoring, detection, and logs for exposed assets that need extra review. Additionally, operators and platform administrators should prioritize patching and review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Vulnerability management teams should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed, and asset inventory managers should review affected product deployments in managed environments and assign an owner for follow-up. The potential operational impact of this vulnerability is significant, as it could allow attackers to inject malicious SQL code and compromise the security of Metabase deployments. Therefore, it is essential for all stakeholders to take immediate action to patch their systems and review their security configurations to prevent potential attacks. The source-confidence limits of this vulnerability are based on the CVE description and NVD detail page, which provide reliable information about the vulnerability. However, defenders should verify the affected scope and severity of the vulnerability in their specific environments to ensure that they are adequately protected.
- Vendor
- Metabase
- Product
- Unknown
- CVSS
- CRITICAL 10
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-10
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-10
- Advisory updated
- 2026-08-26
Who should care
Metabase users and administrators should be aware of this critical vulnerability and take immediate action to patch their systems. This includes reviewing and updating field-filter (dimension) parameters, monitoring for suspicious SQL activity, and ensuring that all users are aware of the potential risks associated with publicly shared cards or dashboards. Security teams should also review compensating controls for exposed systems while remediation is scheduled and verified, and check relevant monitoring, detection, and logs for exposed assets that need extra review. Additionally, operators and platform administrators should prioritize patching and review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Vulnerability management teams should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed, and asset inventory managers should review affected product deployments in managed environments and assign an owner for follow-up. This vulnerability may impact various stakeholders, including Metabase users, administrators, security teams, operators, platform administrators, and vulnerability management teams, who should all take necessary precautions to mitigate the vulnerability. The potential operational impact of this vulnerability is significant, as it could allow attackers to inject malicious SQL code and compromise the security of Metabase deployments. Therefore, it is essential for all stakeholders to take immediate action to patch their systems and review their security configurations to prevent potential attacks. The source-confidence limits of this vulnerability are based on the CVE description and NVD detail page, which provide reliable information about the vulnerability. However, defenders should verify the affected scope and severity of the vulnerability in their specific environments to ensure that they are adequately protected. Overall, this vulnerability requires immediate attention from all stakeholders to prevent potential security breaches and ensure the integrity of Metabase deployments. The review context for this vulnerability includes the CVE-
Technical summary
The vulnerability allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) parameter in Metabase. This could lead to unauthorized data access or modification. Metabase users should prioritize patching to prevent potential SQL injection attacks.
Defensive priority
Metabase users should prioritize patching to prevent potential SQL injection attacks.
Recommended defensive actions
- Patch Metabase to the latest version
- Review and update field-filter (dimension) parameters
- Monitor for suspicious SQL activity
Evidence notes
The CVE description indicates that Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) parameter. The CVSS score is 10, indicating a critical vulnerability. Evidence is limited to the CVE description and NVD detail page. Defenders should verify affected Metabase deployments, review field-filter parameters, and monitor for suspicious SQL activity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72899 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72899
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72899 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72899
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/metabase/metabase/security/advisories/GHSA-r8h2-qpfx-mx59
9119a7d8-5eab-497f-8521-727c672e3725
-
Source reference
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-222-01.json
9119a7d8-5eab-497f-8521-727c672e3725
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.