CVE-2026-72899: Metabase
Critical severity, CVSS 10.0. EPSS: 0.8% chance of exploitation in the next 30 days.
Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) parameter.
Affected products
- Metabase Metabase
Published 2026-08-10. Last modified 2026-08-26.