CVE-2026-72898 · High · CISA KEV

Metabase SQLi: Unauthenticated Admin Access, Data Theft, and Configuration Tampering

Threat Engine Auto-Feed · data current as of 2026-08-12

A critical SQL Injection vulnerability in Metabase allows unauthenticated remote attackers to gain administrator access. This enables them to alter application configurations, steal database credentials, and exfiltrate sensitive data from connected databases. The vulnerability is listed in CISA KEV, indicating active exploitation.

  • CVSS:
  • EPSS percentile: 0.4946
  • Exploitation pressure: 55/100 (High)

Exploitation reality: listed in CISA KEV (exploited in the wild) · EPSS 49th percentile. Threat × Vulnerability from public signals — impact depends on your environment.

Weakness —

SQL Injection occurs when an attacker can insert malicious SQL code into an input field, which is then executed by the database. This allows them to manipulate or extract data, bypass authentication, or even take control of the database.

Who's at risk

Exposure: unknown · Auth: unknown · unknown

Enterprise profiles most at risk

  • Organizations using Metabase for business intelligence and data analytics
  • Financial services organizations (targeted by FIN7, LockBit affiliates, APT38)
  • Technology companies (targeted by APT29, Scattered Spider)

Misconfigurations that escalate it

  • Metabase instances exposed to untrusted networks or the internet
  • Over-privileged database connections within Metabase, allowing broad data access

High-impact scenarios

  • Complete compromise of Metabase instances, leading to administrator access
  • Theft of credentials for all connected databases, enabling further lateral movement
  • Unauthorized access and exfiltration of sensitive data from all databases accessible via Metabase
  • Tampering with Metabase application configurations, potentially disrupting operations or enabling persistence

Likely adversaries

  • FIN7 — Financial services (Assessed)
  • LockBit affiliates — Financial services (Assessed)
  • APT38 (Lazarus) — Financial services (Assessed)
  • APT29 (Cozy Bear) — Technology (Assessed)
  • Scattered Spider — Technology (Assessed)

What to do (defensive)

Detect

  • Monitor Metabase application logs for unusual SQL queries or administrative actions from unknown sources.
  • Look for unexpected changes in Metabase configuration or user accounts.
  • Monitor network traffic for unusual outbound connections from Metabase instances.

Contain

  • Isolate affected Metabase instances from the network.
  • Revoke and rotate all credentials stored within or used by Metabase.
  • Review and restrict database permissions for Metabase connections to the absolute minimum required.

Patch

  • Apply the latest security patches from Metabase immediately to address the SQL Injection vulnerability.

Frontier verdict — High

This is a high-priority vulnerability due to unauthenticated remote administrator access, significant data theft potential, and confirmed in-the-wild exploitation (CISA KEV).

For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.