CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-72899

criticalCVSS 10covered by 2 sourcesfirst seen 2026-08-10
An attacker can exploit multiple vulnerabilities in Metabase to perform SQL injection, thereby gaining administrator privileges, or to disclose confidential information.

CSIRTS triage

What
Multiple vulnerabilities enable SQL injection leading to administrator privilege gain or confidential information disclosure.
Who is affected
Metabase deployments.
Urgency
High severity; sql injection with admin privilege escalation is a critical path to full compromise.
Action
Apply available security patches for Metabase immediately.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-72899

Get an email if CVE-2026-72899 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-72899

CVE.org record

Embed the live status

CVE-2026-72899 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-72899 status](https://www.csirts.com/badge/CVE-2026-72899)](https://www.csirts.com/cve/CVE-2026-72899)