Metabase Product Security Update Advisory

Metabase Product Security Update Advisory
  • A security update has been released for the Metabase product.
  • The vulnerabilities addressed include two instances of SQL injection (a vulnerability where input is exploited to manipulate database queries) and one vulnerability that exposes sensitive information in the application database to users with low privileges.
  • The related CVEs are CVE-2026-72898, CVE-2026-72899, and CVE-2026-72900.
  • The affected versions for CVE-2026-72898 are x.58.0 Through x.58.22, X.59.0 Through x.59.19, X.60.0 Through x.60.15, X.61.0 Through x.61.9, X.62.0 Through x.62.7, And x.63.0 Through x.63.2.
  • The Affected Versions are x.58.0 Or higher through x.58.23, X.59.0 Or higher through x.59.20, X.60.0 Or higher through x.60.16, X.61.0 Or higher through x.61.10, X.62.0 Or higher through x.62.8, And x.63.0 Or higher through x.63.4.
  • For CVE-2026-72898, the patched versions are x.58.24, X.59.21, X.60.17, X.61.11, X.62.9, X.63.5.
  • The patched versions for CVE-2026-72899 and CVE-2026-72900 are also x.58.24, X.59.21, X.60.17, X.61.11, X.62.9, And x.63.5.
  • The reference site lists the following vulnerabilities: SQL injection using an unauthenticated endpoint leading to admin access, SQL injection using a publicly shared dashboard leading to admin access, and Leaking sensitive data from the application database to low-privilege Metabase users.