Metabase patches multiple SQLi flaws
ANSSI advisory details multiple vulnerabilities in Metabase, including SQL injection and data confidentiality issues, fixed in recent releases.
ANSSI (France's CERT) issued an advisory covering multiple vulnerabilities disclosed by Metabase, an open-source business intelligence and analytics tool. The flaws include a SQL injection vulnerability, an information disclosure issue affecting data confidentiality, and an additional security issue not further specified by the vendor. Four GitHub security advisories (GHSA-8hmm-hrhg-ppqp, GHSA-r8h2-qpfx-mx59, GHSA-vwf4-m7j8-wcjf, GHSA-r495-55cx-fjh7) published in August 2026 correspond to three CVEs: CVE-2026-72898, CVE-2026-72899, and CVE-2026-72900.
Affected versions span multiple release branches: versions prior to x.58.28, x.63.10, x.59.25, x.60.21, x.61.15, and x.62.13. Organizations running self-hosted Metabase instances should identify their branch and version, and upgrade to the fixed releases referenced in the vendor's security advisories. No indication of active exploitation in the wild is provided in this advisory; it is a standard vendor-patch notification distributed through ANSSI's alert channel.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1075
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free