A critical security flaw in Metabase, a widely used business analytics and reporting tool, is being actively exploited right now to steal data from connected databases.
- What it is: An unauthenticated bug (CVE-2026-72898) lets an attacker log in as an administrator without a password, then read or extract every database connected to the tool.
- Who is affected: Businesses running a self-hosted Metabase instance (versions 0.58/1.58 through 0.63.4). Several companies have already had customer data and login keys stolen this way.
- What the risk is: Once inside, attackers can view, copy or destroy connected databases, and create hidden admin accounts for ongoing access.
- What to do: Patch to the latest Metabase version immediately, or take internet-facing instances offline until patched. If you use Google's hosted Metabase Cloud, no action is needed on your end.
If your business relies on Metabase or a similar self-hosted reporting tool, we recommend confirming with your IT provider today that it has been patched.