VORANT. Threat Intelligence Sign in Get the full feed

Metabase patches multiple SQLi flaws

high vulnerability technology

ANSSI advisory details multiple vulnerabilities in Metabase, including SQL injection and data confidentiality issues, fixed in recent releases.

ANSSI (France's CERT) issued an advisory covering multiple vulnerabilities disclosed by Metabase, an open-source business intelligence and analytics tool. The flaws include a SQL injection vulnerability, an information disclosure issue affecting data confidentiality, and an additional security issue not further specified by the vendor. Four GitHub security advisories (GHSA-8hmm-hrhg-ppqp, GHSA-r8h2-qpfx-mx59, GHSA-vwf4-m7j8-wcjf, GHSA-r495-55cx-fjh7) published in August 2026 correspond to three CVEs: CVE-2026-72898, CVE-2026-72899, and CVE-2026-72900.

Affected versions span multiple release branches: versions prior to x.58.28, x.63.10, x.59.25, x.60.21, x.61.15, and x.62.13. Organizations running self-hosted Metabase instances should identify their branch and version, and upgrade to the fixed releases referenced in the vendor's security advisories. No indication of active exploitation in the wild is provided in this advisory; it is a standard vendor-patch notification distributed through ANSSI's alert channel.

Mentioned in this report

Vulnerabilities CVE-2026-72898KEVCVE-2026-72899CVE-2026-72900

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1075

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free