CVE-2026-72899: Metabase

Critical severity, CVSS 10.0. EPSS: 0.8% chance of exploitation in the next 30 days.

Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) parameter.

Affected products

Published 2026-08-10. Last modified 2026-08-26.