Vulnerabilities & Exploits · Web App Attack

Metabase Exploitation Exposes Connected Databases

CSIRT Italia said on August 11 that Metabase CVE-2026-72898 is being actively exploited in the wild, while NCSC-NL separately issued a Power BI Server advisory for CVE-2026-65811. Metabase’s fixes cover affected x.58 through x.63 branches.

The Metabase flaw sits in the password-reset path: attacker-supplied SQL can slip past the login checks and land an attacker in an admin session. Once inside, Metabase can expose the database credentials it stores for connected systems, so the problem is not limited to the dashboard itself.

For teams that use BI tools as the front end to internal data, the durable exposure is whatever databases the platform can already reach. The Power BI issue is a different class of problem: it needs prior authentication and, unlike Metabase, was not reported as exploited.

7 sources · Aug 12

CVE-2026-72898

NVD KEV

Known exploited · CISA KEV

CVSS 10 CRITICAL: metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database…

CISA federal remediation date Aug 14

CVE-2026-65811

NVD KEV

CVSS 8.8 HIGH: improper input validation in Power BI allows an authorized attacker to execute code over a network. Microsoft patch: Release Notes.

Timeline

Sources

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-08-09

Every edition of this story: Metabase Exploitation Exposes Connected Databases

More from today