Tag: Metabase

Week 36 – Critical Metabase SQL Injection Scores a Perfect 10

31 Aug – 06 Sept 2026 A critical CVSS 10.0 vulnerability puts the spotlight on one of the oldest tricks in the hacker’s toolbox: SQL injection. This week’s CVE of the Week, CVE-2026-72898, affects self-hosted Metabase Community and Enterprise/Pro deployments and can allow unauthenticated attackers