12 August 2026
Reference: CVE-2026-72898
1. What is being reported?
The Metabase software has a security problem where someone can send special commands through the password reset feature to run harmful database instructions. This can let them gain administrator access without needing a password.
2. What this means in plain English
If your organisation uses Metabase, an attacker could potentially access all your data and control the system, which could lead to data theft, loss, or disruption of your services.
3. Could this affect a small business?
Small businesses or charities using Metabase, especially if it is accessible over the internet, are at risk. Those not using Metabase or who have it isolated from external access are less likely to be affected.
4. What to do now
- Contact your IT provider or software supplier immediately to check if you use Metabase and if this vulnerability affects your setup.
- Apply any security updates or patches provided by Metabase as soon as possible.
- If updates are not yet available, follow any recommended mitigations from Metabase or consider temporarily disabling the service.
- Review your system’s exposure to the internet and restrict access to Metabase where possible.
5. Ask your IT provider
Can you confirm if our Metabase installation is affected by CVE-2026-72898, and what steps are being taken to secure it against this critical vulnerability?
6. Bottom line
If you use Metabase, act quickly to update or protect it to prevent attackers from taking control of your data.
Information based on CISA KEV, NVD, and reputable security reporting.