Review reviewCritical
CVE-2026-72899
Metabase
Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) parameter.
- CVSS
- 10
- EPSS
- - - percentile
- CISA KEV
- Not listed
- Published
- 2026.08.11