CVE-2026-72898: Metabase Metabase
Metabase包含一個SQL注射弱點,允許一個未經認證的遠端攻擊者將任意的SQL隱碼攻擊Metabase應用資料庫,這可以讓他們管理員訪問例項。從那裡,攻擊者可以改變應用程式配置,竊取所儲存的連線資料庫的證書,讀取透過這些連線可以獲取的任何資料,並匯出資料。
CISA (English)
Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.
- 廠商
- Metabase
- 產品
- Metabase
- 漏洞
- Metabase SQL Injection Vulnerability
- 加入日期
- 2026年8月11日
- CISA 修補期限(美國聯邦機關)
- 2026年8月14日
- 已知用於勒索軟體攻擊
- 未知
- 弱點(CWE)
- CWE-89
參考資料
本站僅為資訊目的整理 CISA 目錄,並非資安建議。請遵循廠商指引與官方公告。
最後更新: · 目錄版本 2026.10.02