Metabase · Metabase
Updated August 17, 2026
A SQL Injection vulnerability in Metabase allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database. This vulnerability is critical because it can be exploited by an unauthenticated attacker, potentially giving them administrator access to the instance. The vulnerability's impact is increased due to its ease of exploitation and potential for significant data breaches.
If left unpatched, this vulnerability could lead to unauthorized access to sensitive information, potential data breaches, and significant financial losses. An attacker could exploit this vulnerability to steal stored credentials, read any data accessible through connected databases, and export data.
Apply the latest security patch from Metabase to mitigate this vulnerability. Ensure that all affected instances are updated as soon as possible to prevent potential attacks.
More active vulnerabilities