CISA added CVE-2026-72898 to its Known Exploited Vulnerabilities catalog following evidence of widespread, active exploitation. The bug affects Metabase, a popular open-source business intelligence and analytics platform used extensively across technology firms and Web3 startups.
The vulnerability is a high-severity SQL injection flaw located in Metabase’s internal session handling API. Remote attackers can issue crafted SQL payloads to bypass authentication controls, extract underlying system configuration parameters, and execute arbitrary database queries against connected storage nodes.
The Pipeline to Crypto Theft
Business intelligence engines consolidate data from production databases, payment gateways, and user registries:
Extraction of Cleartext DB Credentials: Metabase stores encrypted and cached connection strings for primary databases (PostgreSQL, MySQL, Snowflake). Exploiting CVE-2026-72898 enables attackers to dump these stored credentials, granting direct access to backend application databases.
User-to-Wallet Mapping Exfiltration: Attackers gain access to databases containing customer identities, email records, and corresponding cryptocurrency wallet addresses—providing the exact dataset needed to execute precision spear-phishing, SIM-swaps, and account takeovers.