
CISA Warns of Actively Exploited Metabase Flaw Enabling Admin Account Takeover
A critical SQL injection vulnerability in Metabase, tracked as CVE-2026-72898, could allow unauthenticated remote attackers to compromise vulnerable instances and obtain administrator-level control. The flaw, classified under CWE-89, affects the application’s own database layer and creates a path to expose connected data sources, stored credentials, and sensitive business intelligence records. The issue was added to […]
The post CISA Warns of Actively Exploited Metabase Flaw Enabling Admin Account Takeover appeared first on Cyber Security News.