Description
Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database.
Published: 2026-08-10
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Metabase has a defect that permits an attacker who is authenticated but holds only low-level privileges to read the entire application database. vulnerability stems from missing authorization checks when accessing database content, allowing privileged users to bypass restrictions. This can lead to widespread exposure of sensitive data stored in the application, compromising confidentiality and potentially revealing personal or proprietary information.

Affected Systems

The flaw affects the Metabase application. Any installation of Metabase that includes the default database schema is susceptible, regardless of deployment environment. No specific version information is provided, so all current releases are potentially impacted until mitigated.

Risk and Exploitability

The CVSS score for this issue is 7.1, indicating a substantial impact. No EPSS value is available, so the exploitation probability cannot be quantified with current data. The vulnerability is not listed in the CISA KEV catalog, but the requirement for merely possessing a low-privilege account makes it potentially attractive to attackers inside an organization. Exploitation likely follows a path where an authenticated user accesses privileged endpoints that are incorrectly guarded, inadvertently retrieving the full database contents, and the attack vector is inferred from the description; the vulnerability description only indicates that a low‑privileged attacker can read the entire application database.

Generated by OpenCVE AI on August 10, 2026 at 20:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest Metabase release that includes the fix for the missing authorization check.
  • Restrict low‑privileged user permissions to prevent access to sensitive database tables and endpoints.
  • Monitor database and application logs for unauthorized read operations and audit privileged account activity.

Generated by OpenCVE AI on August 10, 2026 at 20:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Description Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database.
Title Metabase information exposure
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-08-10T20:04:45.028Z

Reserved: 2026-08-10T17:21:18.799Z

Link: CVE-2026-72900

cve-icon Vulnrichment

Updated: 2026-08-10T20:04:36.965Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T20:15:03Z

Weaknesses