# Metabase patches multiple SQLi flaws

Published: 2026-08-24 · Severity: high · Sectors: technology
Canonical: https://vorant.io/reports/d3464a42-3fc2-5603-9f9f-5134e3ef79f4/metabase-patches-multiple-sqli-flaws

> ANSSI advisory details multiple vulnerabilities in Metabase, including SQL injection and data confidentiality issues, fixed in recent releases.

ANSSI (France's CERT) issued an advisory covering multiple vulnerabilities disclosed by Metabase, an open-source business intelligence and analytics tool. The flaws include a SQL injection vulnerability, an information disclosure issue affecting data confidentiality, and an additional security issue not further specified by the vendor. Four GitHub security advisories (GHSA-8hmm-hrhg-ppqp, GHSA-r8h2-qpfx-mx59, GHSA-vwf4-m7j8-wcjf, GHSA-r495-55cx-fjh7) published in August 2026 correspond to three CVEs: CVE-2026-72898, CVE-2026-72899, and CVE-2026-72900.

Affected versions span multiple release branches: versions prior to x.58.28, x.63.10, x.59.25, x.60.21, x.61.15, and x.62.13. Organizations running self-hosted Metabase instances should identify their branch and version, and upgrade to the fixed releases referenced in the vendor's security advisories. No indication of active exploitation in the wild is provided in this advisory; it is a standard vendor-patch notification distributed through ANSSI's alert channel.

## Mentioned in this report

- Vulnerabilities: CVE-2026-72898 (KEV), CVE-2026-72899, CVE-2026-72900

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1075

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/d3464a42-3fc2-5603-9f9f-5134e3ef79f4/metabase-patches-multiple-sqli-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
