CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-72900

highCVSS 6.5covered by 2 sourcesfirst seen 2026-08-10
An attacker can exploit multiple vulnerabilities in Metabase to perform SQL injection, thereby gaining administrator privileges, or to disclose confidential information.

CSIRTS triage

What
Multiple vulnerabilities enable SQL injection leading to administrator privilege gain or confidential information disclosure.
Who is affected
Metabase deployments.
Urgency
High severity; sql injection with admin privilege escalation is a critical path to full compromise.
Action
Apply available security patches for Metabase immediately.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-72900

Get an email if CVE-2026-72900 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-72900

CVE.org record

Embed the live status

CVE-2026-72900 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-72900 status](https://www.csirts.com/badge/CVE-2026-72900)](https://www.csirts.com/cve/CVE-2026-72900)