What is CVE-2026-72898?
CVE-2026-72898 is a vulnerability classified as Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), affecting Metabase (affected versions: x.58.0 – < x.58.24, x.59.0 – < x.59.21, and other affected versions). This vulnerability is rated Critical, with a CVSS score of 10. This vulnerability has been observed being exploited in the wild.