A security update has been released for the Metabase product. The vulnerabilities addressed include two instances of SQL injection (a vulnerability where input is exploited to manipulate database queries) and one vulnerability that exposes sensitive information in the application database to users with low privileges. The related CVEs are CVE-2026-72898,