Exploited Vulnerabilities Daily
🌐 한국어

← 전체 신규 항목

CVE-2026-72898: Metabase Metabase

Metabase는 Metabase 애플리케이션 데이터베이스에 arbitrary SQL을 주사하기 위해 unauthenticated Remote attacker를 허용하는 SQL Injection vulnerability를 포함합니다. 예를 들어 관리자 액세스를 제공 할 수 있습니다. 거기에서 공격자는 애플리케이션 구성을 변경할 수 있으며 연결된 데이터베이스에 저장된 자격 증명을 훔치며 해당 연결 및 수출 데이터를 통해 액세스 할 수있는 데이터를 읽을 수 있습니다.

CISA (English)

Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.

공급업체
Metabase
제품
Metabase
취약점
Metabase SQL Injection Vulnerability
추가일
2026. 8. 11.
CISA 조치 기한(미국 연방기관)
2026. 8. 14.
랜섬웨어 공격 악용
알 수 없음
약점(CWE)
CWE-89

참고 자료

이 사이트는 정보 제공 목적으로 CISA 카탈로그를 요약한 것이며 보안 조언이 아닙니다. 공급업체 안내와 공식 권고를 따르세요.

최종 업데이트: · 카탈로그 버전 2026.10.02