CVE-2026-72899

Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) parameter.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-10 18:18

Updated : 2026-08-26 16:52


NVD link : CVE-2026-72899

Mitre link : CVE-2026-72899

CVE.ORG link : CVE-2026-72899


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')