SQL Injection Vulnerability in Metabase Affects Data Security
CVE-2026-72899
10CRITICAL
What is CVE-2026-72899?
A vulnerability in Metabase enables unauthenticated users to execute arbitrary SQL commands through shared cards or dashboards, compromising data integrity and security. This issue arises specifically when a field-filter parameter is publicly exposed, allowing potential attackers to exploit the data environment without any form of user authentication.
Affected Version(s)
Metabase x.58.0
Metabase x.59.0
Metabase x.60.0
