We use cookies on this website.

By clicking "Accept," you agree to the storage of cookies on your device to improve your browsing experience, analyze site usage, and contribute to our marketing efforts. See our privacy policy for more information.

Cybersecurity

Metabase Vulnerability (CVE-2026-72898): Should SMEs Apply the Patch Immediately?

On August 24, 2026, CERT-FR issued an advisory regarding several vulnerabilities in Metabase, a widely used dashboard tool among small and medium-sized businesses. A few days earlier, the French service provider TeleCoop confirmed that its own instance had been compromised. How to decide whether your company should apply the patch today or next week.

Metabase Vulnerability (CVE-2026-72898): Should SMEs Apply the Patch Immediately?

In summary. On August 24, 2026, CERT-FR issued an advisory regarding several vulnerabilities in Metabase, a data visualization tool that many small and medium-sized businesses host themselves. A French service provider, TeleCoop, has already had its instance compromised and has notified its customers, which gives a concrete idea of what this type of vulnerability can lead to.

What Happened

Metabase is used to build dashboards from enterprise databases: billing, production, CRM, and support. The vendor released security bulletins on August 6 and 11, 2026. On August 24, CERT-FR relayed this information in advisory CERTFR-2026-AVI-1075, which references vulnerabilities CVE-2026-72898, CVE-2026-72899, and CVE-2026-72900. The reported risks: data confidentiality breaches and SQL injection.

The sensitive issue lies in the nature of the tool. Metabase connects to the company’s databases and stores their credentials. Gaining control of the application therefore potentially means gaining read access to everything it queries.

The TeleCoop case is a good illustration of this scenario. The cooperative telecom operator reports that its monitoring platform was compromised between August 18 and 19, after the authentication mechanism was bypassed. Alerted on August 19 by government agencies, it deployed the patch on the 20th and notified its subscribers even before the attackers made their claim public. On August 25, a group calling itself X-VDP-X claimed responsibility for the exfiltration of 15 databases and 2,661 tables, including more than 16,000 email addresses. TeleCoop, for its part, states that banking information, passwords, and identification documents were not compromised. The two sets of data do not match, and there is currently no way to determine which is correct.

Does this apply to me?

The right question isn't "Do we have Metabase?" but "Has someone here installed Metabase?" This is typically the kind of tool that a business team, a developer, or a third-party vendor sets up on a server or in a container without going through the IT department. It often ends up exposed on the Internet because it's more convenient to access it from outside the network.

Three real-life situations:

  • You host Metabase yourself, either on-premises or on a rented server. Applying the patch is your responsibility; no one will do it for you.
  • You are using the vendor's cloud service. The update is performed on the vendor's end, but some customers of this service have reported unauthorized access: request written confirmation regarding your environment.
  • A service provider maintains a dashboard for you. The question is sent back to them in writing, along with a deadline for a response.

To get started, the version displayed on the login screen is all you need. The CERT-FR advisory lists the patched versions.

What to Do Now

1. First, check the exposure, not the score. An instance that’s accessible via the Internet and hasn’t been patched is typically resolved within a day or taken offline until it’s updated. An instance accessible only via VPN gives you a few days. This criterion—not the number reported in the media—should determine the level of urgency.

2. Renew the credentials for the connected databases. If the application remained exposed without a patch, assume that the passwords for the databases it queries have been compromised. Change them, and do the same for the associated API tokens.

3. Review the logs before closing them. Unusual administrator logins, large exports, repeated API calls: these traces answer the key question that follows—whether you need to notify the CNIL within 72 hours. If your organization falls under NIS 2, additional reporting requirements apply.

Not sure about your exposure?

Get an update from an IT Systems expert

A quick assessment of your exposure and the steps you should take. No obligation.

Request an exchange

In a nutshell

Not every vulnerability warrants a sleepless night. This one warrants a check during the day if your dashboard tool is accessible over the Internet, because it holds the keys to your databases. The decision depends on the exposure and sensitivity of the data the application handles.

TeleCoop resolved the issue within 24 hours and notified its customers before the attackers could act. A well-managed incident is still an incident, but it costs significantly less than one that goes unchecked. This is also the benefit of maintaining an up-to-date inventory of your exposed systems.

Frequently asked questions

Should we stop using Metabase? No. The issue here is the update delay and online exposure, not the quality of the tool.

We're a small organization—are we really a target? Attackers scan the Internet and exploit whatever they find. The size of the company doesn't factor into their calculations.

How can you tell what was actually accessed? By checking the application logs and the database logs. That's why it's important to keep them and centralize them before an incident occurs, not after.

— Samir Amara, CEO — IT Systèmes

Our latest articles

See more
Helpy Barometer: Resolution rate for Level 1 tickets measured on the IT Systèmes internal help desk

Helpy 2026 Barometer: 44% of Level 1 tickets resolved without human intervention

44% of Level 1 tickets resolved without human intervention, 3-minute average resolution time, €0.26 per ticket. Eleven months of data collected from our own help desk, including methodology and limitations.
August 27, 2026
IT Security Governance and Steering Meeting in an Open-Plan Office
Cybersecurity

Cybersecurity GRC: Governance, Risk, and Compliance—A Guide for Small and Medium-Sized Businesses

GRC (Governance, Risk, and Compliance) provides a framework for managing IT security. Definition, clarification of differences from CRM, pillars, relationship with NIS2, and implementation for small and medium-sized businesses and mid-sized companies.
August 27, 2026
Abstract illustration of a data flow related to an artificial intelligence platform
Cybersecurity

Claimed Data Breach at Klark.ai: The Real Risk for Small and Medium-Sized Businesses Using AI Tools

A hacker has claimed responsibility for stealing more than 140 GB of data from Klark.ai, a French AI platform dedicated to customer service. Approximately 500,000 people are reportedly affected, with support conversations, API keys, and a few IBANs among the stolen data. Here’s how to tell if your small business is indirectly at risk—and the three checks you should perform this week.
August 27, 2026

Confidential Computing in 2026: Protecting Your Data Even in Memory, on a Third-Party Cloud

‍Confidential computing encrypts data while it is being processed in memory, not just at rest or in transit. This guide explains what the technology actually protects, what it does not protect according to ANSSI, and how a CIO at an SME or mid-sized company should take this into account when making cloud decisions.
August 26, 2026
Cybersecurity

Tax Agency Hack: What Leaked From the Corporate Side, and the 3 Checks to Perform This Week

The DGFiP has confirmed the theft of data belonging to 678,000 users—both individuals and businesses—following a breach of its information system in late June. For businesses, the scope of the data breach is limited (SIREN numbers, addresses), but this information is enough to make a phishing attempt or wire transfer fraud much more credible. Here’s what was actually leaked and the steps you should take this week.
August 17, 2026
Data & AI

Is Claude in Chrome secure? Passwords (2026)

Claude can fill in a password without ever seeing it, under one specific condition. Anthropic recommendations, vulnerability fixed in 2026, CIO checklist.
August 17, 2026