Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4996 articles · 189019 vulns · 37/41 feeds (7d)
← Back to list
6.5
CVE-2026-72900PATCHED
metaba · metaba

Metabase information exposure

Description

Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database.

Affected Products

VendorProductVersions
metabametabax.58.0, x.59.0, x.60.0, x.61.0, x.62.0, x.63.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
metabametabasecert_advisory90%

References

  • https://github.com/metabase/metabase/security/advisories/GHSA-8hmm-hrhg-ppqp(vendor-advisory)
  • https://www.cve.org/CVERecord?id=CVE-2026-72900(vdb-entry)
  • https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-222-01.json(third-party-advisory)

Related News (2 articles)

Tier B
BSI Advisories1d ago
[NEU] [hoch] Metabase: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB2d ago
CVE-2026-72900 | Metabase up to x.63.4 information disclosure
→ No new info (linked only)
CVSS 3.16.5 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
x.58.24x.59.21x.60.17x.61.11x.62.9x.63.5
CWECWE-862
PublishedAug 10, 2026
Trending Score30
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-72898EXPKEV
Metabase SQL injection via password reset endpoint
Trending: 119
CRITICALCVE-2026-72899
Metabase SQL injection via public card or dashboard
Trending: 49
CRITICALCVE-2026-50148
Metabase: Remote Code Execution via Snowflake JDBC Driver Arbitrary File Write
Trending: 2
HIGHCVE-2026-50147EXP
Metabase: Arbitrary File Read via MySQL Connection Property Injection
Trending: 1
CRITICALCVE-2026-59826EXP
Metabase: Arbitrary Code Execution via Database Connection Detail Bypass

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 10, 2026
Discovered by ZDM
Aug 10, 2026
Patch Available
Aug 10, 2026