CVE-2026-72899 - Metabase SQL injection via public card or dashboard
CVE ID :CVE-2026-72899
Published : Aug. 10, 2026, 6:18 p.m. | 1 hour, 9 minutes ago
Description :Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) parameter.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 10, 2026, 6:18 p.m. | 1 hour, 9 minutes ago
Description :Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) parameter.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...