<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Metabase</title><description>Actively exploited vulnerabilities affecting Metabase products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/metabase.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-72898 — Metabase SQL Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-72898</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-72898</guid><description>This SQL injection flaw in Metabase requires no authentication, meaning any internet-accessible Metabase instance can be compromised without credentials. An attacker who exploits it gains administrator-level control, enabling them to alter application settings, harvest credentials for all connected databases, and exfiltrate any data those databases can reach. The breadth of potential data exposure — spanning the Metabase application itself and every downstream data source it connects to — makes this a high-priority risk for any organization running Metabase.</description><pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate><category>Metabase</category><category>Metabase</category></item></channel></rss>