Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

Critical Security Flaw in Metabase Could Let Hackers Take Over Your Data

A serious security weakness has been found in Metabase, a popular data analysis tool. This flaw lets attackers who are not logged in inject harmful commands to take full control of the system. Because this vulnerability is actively being exploited, it poses a significant risk to organisations using Metabase without proper updates or protections.

12 August 2026

Reference: CVE-2026-72898

1. What is being reported?

The Metabase software has a security problem where someone can send special commands through the password reset feature to run harmful database instructions. This can let them gain administrator access without needing a password.

2. What this means in plain English

If your organisation uses Metabase, an attacker could potentially access all your data and control the system, which could lead to data theft, loss, or disruption of your services.

3. Could this affect a small business?

Small businesses or charities using Metabase, especially if it is accessible over the internet, are at risk. Those not using Metabase or who have it isolated from external access are less likely to be affected.

4. What to do now

  • Contact your IT provider or software supplier immediately to check if you use Metabase and if this vulnerability affects your setup.
  • Apply any security updates or patches provided by Metabase as soon as possible.
  • If updates are not yet available, follow any recommended mitigations from Metabase or consider temporarily disabling the service.
  • Review your system’s exposure to the internet and restrict access to Metabase where possible.

5. Ask your IT provider

Can you confirm if our Metabase installation is affected by CVE-2026-72898, and what steps are being taken to secure it against this critical vulnerability?

6. Bottom line

If you use Metabase, act quickly to update or protect it to prevent attackers from taking control of your data.

Information based on CISA KEV, NVD, and reputable security reporting.

Back to Vulnerability Briefs