Metabase SQL Injection Vulnerability

Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.

Published 10 Aug 2026Updated 10 Aug 20268 sources
CVSS 0.0 △ CISA KEV

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.