PatchSiren

metabase CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM metabase CVE published 2026-09-16

CVE-2026-92813

Metabase through 0.63.18 fails to properly validate the unspecified address 0.0.0.0 in custom GeoJSON URLs, allowing unauthenticated attackers to reach loopback services. This vulnerability enables attackers to save a malicious GeoJSON entry with 0.0.0.0 and trigger requests that return loopback service responses to unauthenticated callers, potentially bypassing security controls and exposing internal ser [truncated]

HIGH Metabase CVE published 2026-08-10

CVE-2026-72900

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T18:18:53.637Z and has not been modified since then. CVE-2026-72900 is a HIGH severity vulnerability in Metabase, allowing authenticated, low-privileged attackers to read the entire application database, with a CVSS score of 7.1. The vulnerability affects Metabase application databases, and defend [truncated]

CRITICAL Metabase CVE published 2026-08-10

CVE-2026-72899

Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) parameter. The CVE record was published on 2026-08-10T18:18:53.490Z and has not been modified since then. This vulnerability, with a CVSS score of 10, is critical and could lead to unauthorized data access or modification. Metabase users and administrators sho [truncated]

CRITICAL metabase CVE published 2026-07-15

CVE-2026-50148

A critical vulnerability was discovered in Metabase, an open-source business intelligence and embedded analytics tool. The issue, tracked as CVE-2026-50148, allows a Metabase user with permission to add or edit a database connection to achieve remote code execution on the Metabase server. This is possible by configuring a Snowflake connection to an attacker-controlled server, exploiting a flaw in the Snow [truncated]

CRITICAL metabase CVE published 2026-07-09

CVE-2026-59827

Metabase is vulnerable to code execution. Instances with an H2 database connection, including the default sample database, deserialize arbitrary Java objects returned in H2 native query result columns of type OTHER without validation. An authenticated user who can run native H2 queries can execute code on the Metabase server. This issue is fixed in versions 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4. The vu [truncated]

CRITICAL metabase CVE published 2026-07-09

CVE-2026-59826

Metabase, an open-source business intelligence tool, had a critical vulnerability (CVE-2026-59826, CVSS score of 9.1) in versions from 1.55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2. The issue allowed authenticated administrators to register a crafted H2 database connection and execute arbitrary Java code on the Metabase server due to a lack of validation of unsafe H2 connection properties. This vu [truncated]

Known exploited Metabase CVE published 2024-11-12

CVE-2021-41277

CVE-2021-41277 is a Metabase GeoJSON API local file inclusion vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2024-11-12. The KEV listing means CISA has determined the issue has been exploited in the wild, so exposed Metabase deployments should be treated as a priority remediation item. The supplied records do not include a CVSS score, so prioritization here is driven by kn [truncated]