CISA KEV Alert 8/11/2026, 10:37:02 PM

CISA adds critical Metabase SQLi flaw to KEV, urges patch

CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Available

ON 11 August 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE‑2026‑72898 to its Known Exploited Vulnerabilities (KEV) catalogue. The flaw affects Metabase, the open‑source business‑intelligence platform, and is identified as the Metabase SQL Injection Vulnerability. It allows an unauthenticated remote attacker to inject arbitrary SQL into the application’s database, potentially granting administrator access.

The vulnerability is a classic SQL injection that can be exploited over the network without authentication, leading to full compromise of the Metabase instance. Successful exploitation enables an attacker to alter configuration, harvest credentials for connected databases, read any data reachable via those connections, and export information. The CVSS v3.1 base score is 10.0, rated Critical. A patch is available from the vendor.

CISA’s inclusion in the KEV catalogue confirms that the flaw is being actively exploited in the wild. No public reports link this vulnerability to ransomware campaigns at this time. Federal civilian executive branch (FCEB) agencies must apply the required mitigations by 14 August 2026, the remediation deadline set by CISA.

CISA directs stakeholders to apply mitigations in line with vendor instructions, ensuring compliance with BOD 26‑04 Prioritising Security Updates Based on Risk and the associated Forensics Triage Requirements. For cloud‑based deployments, agencies should follow the relevant BOD 26‑04 guidance or discontinue use if mitigations cannot be applied. All organisations should review their exposure to Metabase and verify that the update or other mitigations are in place.

For full technical details, see the NVD entry at https://nvd.nist.gov/vuln/detail/CVE-2026-72898 and the CISA KEV catalogue entry.

View CISA KEV Entry

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline