CVSS 10.0 Doesn't Happen Often. Metabase Earned It.
CVE-2026-72898. CVSS score 10.0 out of 10.0. Perfect score. Maximum severity.
Metabase disclosed it August 6, 2026. It's a SQL injection vulnerability that lets unauthenticated remote attackers inject arbitrary SQL into the Metabase application database and gain administrator access (Metabase GHSA-vwf4-m7j8-wcjf, August 6, 2026; Wiz Security, August 2026).
No credentials needed. No authentication. Just a payload and you're in.
Framework, the San Francisco laptop manufacturer, confirmed the breach via this zero-day. Attackers accessed customer names, email addresses, phone numbers, physical addresses, and login IP addresses. Payment information wasn't compromised, but that's the only part that wasn't (Framework disclosure, August 2026; BleepingComputer, August 10, 2026).
What a 10.0 Actually Means
CVSS 10.0 is reserved for the worst-case vulnerabilities. Unauthenticated remote code execution. Complete system takeover. Data theft. Admin access.
CVE-2026-72898 checks every box.
Metabase is a business intelligence platform. Organizations connect it to their production databases to build dashboards and run analytics. Customer data. Revenue figures. Internal metrics. Everything that matters, in one place, behind one web interface.
An unauthenticated SQL injection means anyone who can reach that interface can inject commands directly into the application database, alter configuration, steal credentials for the connected databases, read everything those databases hold, and export it (Wiz Security, August 2026; The Hacker News, August 10, 2026).
Framework's breach is proof it happened. But Metabase is used by thousands of companies, most of whom don't know they were hit yet.
Metabase Cloud Got Hit Too
This wasn't just self-hosted instances. Metabase Cloud — the vendor-managed, supposedly-hardened hosted version — was exploited (HelpNetSecurity, August 10, 2026).
That means the attackers had the exploit before Metabase patched it. That's what zero-day means. And if they had it for Metabase Cloud, they had it for every internet-facing Metabase instance.
Patched versions: 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, 0.63.5. Affected versions: Metabase 58 and above (Metabase GHSA-vwf4-m7j8-wcjf, August 6, 2026).
If you're running Metabase on-premises and you haven't patched, you're already breached. You just don't know it yet.
What Framework Lost
Framework's disclosure was precise: names, emails, phone numbers, physical addresses, login IPs. No payment data. No order records (Framework breach disclosure, August 2026; BleepingComputer, August 10, 2026).
That's identity theft. Phishing. Account takeover. Credential stuffing. Everything you need to impersonate a customer, call their bank, reset their passwords, and walk into their accounts.
Framework makes repairable, upgradeable laptops. Their customers are the kind of people who care about controlling their hardware. And now someone has their home addresses and knows what kind of laptop they own.
Think about that for a second.
The BI Tool as Attack Vector
Metabase isn't unique. Tableau. Looker. Power BI. Every BI platform does the same thing: it sits in the middle, connects to your production databases, and gives your analysts a dashboard.
Which means a BI platform compromise is a database compromise. All of them. At once.
Metabase holds credentials for every database it connects to. Customer tables. Revenue. Transactions. User accounts. The attackers didn't just steal Framework's customer list. They stole access to the databases holding that list.
SQL injection has been on the OWASP Top 10 for over a decade. Input validation is Security 101. And Metabase, a tool whose entire job is querying databases, shipped a vulnerability that let attackers inject arbitrary SQL without authentication.
The Zero-Day Window
The disclosure date is August 6, 2026. The exploitation timeline is unknown (Wiz Security, August 2026).
That means attackers had days, possibly weeks, before Metabase patched and before anyone knew to look for it. Framework found out they were breached. How many others didn't?
Metabase Cloud patched automatically. Self-hosted instances didn't. If you're running Metabase on-premises and your vulnerability-management process takes longer than a week to deploy critical patches, you were exposed.
And if you're running it internet-facing — which most BI tools are, because analysts need access from anywhere — you were trivial to find. Shodan. Censys. A simple port scan.
What Comes Next
Framework disclosed. Most companies won't.
Metabase published the CVE and the patch. The exploit is now public knowledge. Every attacker who missed the zero-day window now has the details.
If you're running Metabase, you patch or you accept that someone can walk in, dump your databases, and leave. There's no third option.
And if you're running any other BI platform, you audit it. Because if Metabase shipped a CVSS 10.0 SQLi in 2026, your BI vendor's input validation is worth checking too.
The Score Doesn't Lie
CVSS 10.0 is rare. It's reserved for vulnerabilities with maximum impact and minimal complexity.
CVE-2026-72898 earned it. Unauthenticated. Remote. SQL injection. Admin access. Data theft. Exploited in the wild. Zero-day.
That's not a vulnerability. That's a keys-to-the-kingdom failure.
Metabase patched it. Framework disclosed it. Thousands of companies are still figuring out if they were hit.
The score is perfect. The response time wasn't.