CVE-2026-72899

Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) parameter.

  • Published Aug 10, 2026
  • CVSS 10.0 critical
  • 0.8% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2026-72899 at the National Vulnerability Database