Metabase · Metabase
Updated August 12, 2026
A SQL Injection vulnerability in Metabase allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, giving them administrator access to the instance. This vulnerability is critical as it could allow an attacker to steal sensitive data and disrupt business operations. Metabase has released patches to address this issue.
If exploited, this vulnerability could allow an attacker to gain administrator access to the Metabase instance, resulting in significant data breaches and potential financial losses. An attacker could also use this vulnerability to disrupt business operations and cause reputational damage.
Apply the latest Metabase security patches to affected instances as soon as possible to prevent exploitation. Ensure that all Metabase instances are running the latest software versions and that input validation is properly configured.