Back to Blog
CVE-2026-72898: Metabase SQLi — Full Database Compromise (June 2026)
vulnerabilities

CVE-2026-72898: Metabase SQLi — Full Database Compromise (June 2026)

breachwire TeamAug 13, 20262 min read

CVE-2026-72898 — Metabase SQL Injection

CVE-2026-72898 is a critical vulnerability in the Metabase analytics platform that enables unauthenticated attackers to execute arbitrary SQL commands, resulting in full database access. This zero-day has been exploited in the wild, with confirmed breaches and no workaround—immediate patching is mandatory.

Attack Vector

Attackers exploit a SQL injection flaw in Metabase’s query handling, sending crafted payloads to vulnerable endpoints. Successful exploitation allows adversaries to exfiltrate or modify sensitive data, create privileged accounts, and escalate privileges. No authentication is required, and exploitation leaves minimal traces unless detailed query and access logs are enabled. Indicators of compromise include unexpected admin account creation, anomalous SQL queries, and unauthorized access to credentials or tokens.

Who Is at Risk

All organizations running unpatched Metabase instances are vulnerable, regardless of deployment type (cloud or on-premises). Confirmed victims include Kilo Code, Tally, Framework, n8n, and ChecklyHQ, with attackers obtaining usernames, email addresses, cloud passwords, API keys, and Slack tokens. Startups and smaller tech companies are especially at risk due to rapid exploitation.

Patch & Mitigate

  • Patch: Upgrade to the latest Metabase release (see vendor advisory) immediately. No workaround is available.
  • Workaround: None. Isolation or disabling Metabase until patched is recommended if immediate upgrade is not possible.
  • Detect: Review Metabase and database logs for unauthorized admin account creation, suspicious SQL queries, and access to credential stores. Monitor for anomalous outbound connections and token usage.

MITRE ATT&CK

  • TA0001 — Initial Access: Attackers leverage exposed Metabase endpoints to gain entry.
  • TA0005 — Defense Evasion: SQLi payloads may evade standard logging and detection.
  • TA0006 — Credential Access: Attackers extract credentials, API keys, and tokens from compromised databases.

Source: https://www.csoonline.com/article/4208307/metabase-sqli-exploit-grants-attackers-total-access.html

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: