In summary. On August 24, 2026, CERT-FR issued an advisory regarding several vulnerabilities in Metabase, a data visualization tool that many small and medium-sized businesses host themselves. A French service provider, TeleCoop, has already had its instance compromised and has notified its customers, which gives a concrete idea of what this type of vulnerability can lead to.
What Happened
Metabase is used to build dashboards from enterprise databases: billing, production, CRM, and support. The vendor released security bulletins on August 6 and 11, 2026. On August 24, CERT-FR relayed this information in advisory CERTFR-2026-AVI-1075, which references vulnerabilities CVE-2026-72898, CVE-2026-72899, and CVE-2026-72900. The reported risks: data confidentiality breaches and SQL injection.
The sensitive issue lies in the nature of the tool. Metabase connects to the company’s databases and stores their credentials. Gaining control of the application therefore potentially means gaining read access to everything it queries.
The TeleCoop case is a good illustration of this scenario. The cooperative telecom operator reports that its monitoring platform was compromised between August 18 and 19, after the authentication mechanism was bypassed. Alerted on August 19 by government agencies, it deployed the patch on the 20th and notified its subscribers even before the attackers made their claim public. On August 25, a group calling itself X-VDP-X claimed responsibility for the exfiltration of 15 databases and 2,661 tables, including more than 16,000 email addresses. TeleCoop, for its part, states that banking information, passwords, and identification documents were not compromised. The two sets of data do not match, and there is currently no way to determine which is correct.
Does this apply to me?
The right question isn't "Do we have Metabase?" but "Has someone here installed Metabase?" This is typically the kind of tool that a business team, a developer, or a third-party vendor sets up on a server or in a container without going through the IT department. It often ends up exposed on the Internet because it's more convenient to access it from outside the network.
Three real-life situations:
- You host Metabase yourself, either on-premises or on a rented server. Applying the patch is your responsibility; no one will do it for you.
- You are using the vendor's cloud service. The update is performed on the vendor's end, but some customers of this service have reported unauthorized access: request written confirmation regarding your environment.
- A service provider maintains a dashboard for you. The question is sent back to them in writing, along with a deadline for a response.
To get started, the version displayed on the login screen is all you need. The CERT-FR advisory lists the patched versions.
What to Do Now
1. First, check the exposure, not the score. An instance that’s accessible via the Internet and hasn’t been patched is typically resolved within a day or taken offline until it’s updated. An instance accessible only via VPN gives you a few days. This criterion—not the number reported in the media—should determine the level of urgency.
2. Renew the credentials for the connected databases. If the application remained exposed without a patch, assume that the passwords for the databases it queries have been compromised. Change them, and do the same for the associated API tokens.
3. Review the logs before closing them. Unusual administrator logins, large exports, repeated API calls: these traces answer the key question that follows—whether you need to notify the CNIL within 72 hours. If your organization falls under NIS 2, additional reporting requirements apply.
Not sure about your exposure?
Get an update from an IT Systems expert
A quick assessment of your exposure and the steps you should take. No obligation.
In a nutshell
Not every vulnerability warrants a sleepless night. This one warrants a check during the day if your dashboard tool is accessible over the Internet, because it holds the keys to your databases. The decision depends on the exposure and sensitivity of the data the application handles.
TeleCoop resolved the issue within 24 hours and notified its customers before the attackers could act. A well-managed incident is still an incident, but it costs significantly less than one that goes unchecked. This is also the benefit of maintaining an up-to-date inventory of your exposed systems.
Frequently asked questions
Should we stop using Metabase? No. The issue here is the update delay and online exposure, not the quality of the tool.
We're a small organization—are we really a target? Attackers scan the Internet and exploit whatever they find. The size of the company doesn't factor into their calculations.
How can you tell what was actually accessed? By checking the application logs and the database logs. That's why it's important to keep them and centralize them before an incident occurs, not after.
— Samir Amara, CEO — IT Systèmes


.jpeg)

.jpeg)

