CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

[NEW] [critical] Metabase: Vulnerability enables SQL injection and privilege escalation

critical
A remote, anonymous attacker can exploit a vulnerability in Metabase to conduct a SQL injection attack and escalate privileges.

CSIRTS triage

What
A vulnerability in Metabase enables SQL injection and privilege escalation attacks.
Who is affected
All Metabase deployments accessible to remote anonymous users.
Urgency
Critical—remote, unauthenticated exploitation; no CVE identifier suggests potential zero-day or reserved CVE.
Action
Apply the latest Metabase security update immediately or restrict network access until patched.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Metabase

Get an email when a new Metabase advisory drops — max one per day, one-click unsubscribe.

Details

Source
CERT-Bund (BSI) Security Advisories (DE · national-cert · site)
Severity
critical
Published
2026-08-11
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2715

Recent advisories for Metabase

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from CERT-Bund (BSI) Security Advisories