Multiples vulnérabilités dans Metabase (24 août 2026)
Multiple vulnerabilities have been discovered in Metabase, allowing attackers to potentially compromise data confidentiality through SQL injection and an unspecified security issue. These vulnerabilities affect older versions of the database tool.
A security advisory from CERT-FR details multiple vulnerabilities within Metabase. These vulnerabilities could lead to an attacker gaining access to sensitive data via SQL injection and a security flaw not explicitly detailed by the vendor. The advisory highlights several affected Metabase versions, including those prior to x.58.28, x.63.10, x.59.x (prior to x.59.25), x.60.x (prior to x.60.21), x.61.x (prior to x.61.15), and x.62.x (prior to x.62.13). The vulnerabilities are linked to CVE identifiers: CVE-2026-72898, CVE-2026-72899, and CVE-2026-72900. Users are advised to consult the Metabase security bulletin for available patches and updates. The bulletin links are: https://github.com/metabase/metabase/security/advisories/GHSA-8hmm-hrhg-ppqp, https://github.com/metabase/metabase/security/advisories/GHSA-r8h2-qpfx-mx59, and https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf.