CVE-2026-72900: Metabase information exposure
Published Aug 10, 2026
·Updated
Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database.
Affected Software
1 affected component
Metabase
Event History
Aug 10, 2026
CVE Published
via MITRE·05:56 PM
Data Sourced
via MITRE·05:56 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:18 PM
DescriptionSeverityWeakness
Jun 23, 58578
Event
via NVD·09:32 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-72900?
CVE-2026-72900 has a medium severity rating of 6.5.
2
How does CVE-2026-72900 affect Metabase?
CVE-2026-72900 allows an authenticated, low-privileged attacker to read the entire Metabase application database.
3
Who is impacted by CVE-2026-72900?
Authenticated users with low privileges in Metabase are at risk due to CVE-2026-72900.
4
What is the potential impact of CVE-2026-72900?
The potential impact of CVE-2026-72900 includes unauthorized access to sensitive information in the Metabase database.
5
How can organizations mitigate CVE-2026-72900?
Organizations can mitigate CVE-2026-72900 by restricting access controls and ensuring proper user permissions within Metabase.