Metabase - The Reporting Tool Tha...
AI
Metabase - The Reporting Tool That Held Every Key, and the Five Companies That Found Out
AI

Tech Talks With Kinsoft by Steven Kinnas

Episode notes

A deep-dive on CVE-2026-72898, the unauthenticated SQL injection zero-day exploited against Metabase Cloud in early August 2026.

Two corrections to our roundup of 17 August, made on air. A CVE has since been assigned - CVE-2026-72898, added to CISA's Known Exploited Vulnerabilities catalogue on 11 August and rated 10.0 under both CVSS v3.1 and v4.0. And LexisNexis has explicitly ruled out any connection between its service outage and this flaw: the similarly-named Nexis Metabase API is an unrelated product, and LexisNexis is not a Metabase Cloud customer.

The timeline. 2 Aug: attacker active in Kilo Code's instance for about four hours. 3 Aug: broader attack on Metabase Cloud; Metabase detects, blocks and patches the same day. 6 Aug: public advisory; Framework notified, and notifies its own customers. 8 Aug: a researcher ... 

Read more