We use cookies on this website.

By clicking "Accept," you agree to the storage of cookies on your device to improve your browsing experience, analyze site usage, and contribute to our marketing efforts. See our privacy policy for more information.

Cybersecurity

Metabase Vulnerability (CVE-2026-72898): Should SMEs Apply the Patch Immediately?

On August 24, 2026, CERT-FR issued an advisory regarding several vulnerabilities in Metabase, a widely used dashboard tool among small and medium-sized businesses. A few days earlier, the French service provider TeleCoop confirmed that its own instance had been compromised. How to decide whether your company should apply the patch today or next week.

Metabase Vulnerability (CVE-2026-72898): Should SMEs Apply the Patch Immediately?

In summary. On August 24, 2026, CERT-FR issued an advisory regarding several vulnerabilities in Metabase, a data visualization tool that many small and medium-sized businesses host themselves. A French service provider, TeleCoop, has already had its instance compromised and has notified its customers, which gives a concrete idea of what this type of vulnerability can lead to.

What Happened

Metabase is used to build dashboards from enterprise databases: billing, production, CRM, and support. The vendor released security bulletins on August 6 and 11, 2026. On August 24, CERT-FR relayed this information in advisory CERTFR-2026-AVI-1075, which references vulnerabilities CVE-2026-72898, CVE-2026-72899, and CVE-2026-72900. The reported risks: data confidentiality breaches and SQL injection.

The sensitive issue lies in the nature of the tool. Metabase connects to the company’s databases and stores their credentials. Gaining control of the application therefore potentially means gaining read access to everything it queries.

The TeleCoop case is a good illustration of this scenario. The cooperative telecom operator reports that its monitoring platform was compromised between August 18 and 19, after the authentication mechanism was bypassed. Alerted on August 19 by government agencies, it deployed the patch on the 20th and notified its subscribers even before the attackers made their claim public. On August 25, a group calling itself X-VDP-X claimed responsibility for the exfiltration of 15 databases and 2,661 tables, including more than 16,000 email addresses. TeleCoop, for its part, states that banking information, passwords, and identification documents were not compromised. The two sets of data do not match, and there is currently no way to determine which is correct.

Does this apply to me?

The right question isn't "Do we have Metabase?" but "Has someone here installed Metabase?" This is typically the kind of tool that a business team, a developer, or a third-party vendor sets up on a server or in a container without going through the IT department. It often ends up exposed on the Internet because it's more convenient to access it from outside the network.

Three real-life situations:

  • You host Metabase yourself, either on-premises or on a rented server. Applying the patch is your responsibility; no one will do it for you.
  • You are using the vendor's cloud service. The update is performed on the vendor's end, but some customers of this service have reported unauthorized access: request written confirmation regarding your environment.
  • A service provider maintains a dashboard for you. The question is sent back to them in writing, along with a deadline for a response.

To get started, the version displayed on the login screen is all you need. The CERT-FR advisory lists the patched versions.

What to Do Now

1. First, check the exposure, not the score. An instance that’s accessible via the Internet and hasn’t been patched is typically resolved within a day or taken offline until it’s updated. An instance accessible only via VPN gives you a few days. This criterion—not the number reported in the media—should determine the level of urgency.

2. Renew the credentials for the connected databases. If the application remained exposed without a patch, assume that the passwords for the databases it queries have been compromised. Change them, and do the same for the associated API tokens.

3. Review the logs before closing them. Unusual administrator logins, large exports, repeated API calls: these traces answer the key question that follows—whether you need to notify the CNIL within 72 hours. If your organization falls under NIS 2, additional reporting requirements apply.

‍

Not sure about your exposure?

Get an update from an IT Systems expert

A quick assessment of your exposure and the steps you should take. No obligation.

Request an exchange

‍

In a nutshell

Not every vulnerability warrants a sleepless night. This one warrants a check during the day if your dashboard tool is accessible over the Internet, because it holds the keys to your databases. The decision depends on the exposure and sensitivity of the data the application handles.

TeleCoop resolved the issue within 24 hours and notified its customers before the attackers could act. A well-managed incident is still an incident, but it costs significantly less than one that goes unchecked. This is also the benefit of maintaining an up-to-date inventory of your exposed systems.

Frequently asked questions

Should we stop using Metabase? No. The issue here is the update delay and online exposure, not the quality of the tool.

We're a small organization—are we really a target? Attackers scan the Internet and exploit whatever they find. The size of the company doesn't factor into their calculations.

How can you tell what was actually accessed? By checking the application logs and the database logs. That's why it's important to keep them and centralize them before an incident occurs, not after.

— Samir Amara, CEO — IT Systèmes

Our latest articles

See more
Logo de Microsoft 365 Copilot
Cybersecurity
Data & AI

Copilot et sur-partage : ce qu'il peut révéler dans Microsoft 365

Copilot ne crée pas de nouveaux accès, il révèle ceux qui existent : six situations de sur-partage à risque, comment les repérer et les corriger.
9/10/2026
illustration defender suite et purview suite
Cybersecurity

Defender Suite et Purview Suite : sécurité E5 pour Business Premium

Defender Suite et Purview Suite ajoutent à Business Premium la sécurité de niveau E5 : contenu, prix catalogue (10 $, 10 $, 15 $), six cas concrets et NIS2.
9/10/2026
Cybersecurity

Fuite Hauts-de-France : ce qu'une PME doit vérifier dans la foulée

Deux prestataires de la région Hauts-de-France auraient été piratés, avec des centaines de milliers de personnes potentiellement concernées selon les revendications de l'attaquant. Voici ce qui est connu, ce qui reste à confirmer et les trois vérifications à faire côté PME.
7/10/2026
Cybersecurity

LLMOps : définition et exploitation des agents IA en production

LLMOps : définition, différence avec le MLOps et l'AIOps, et les six briques pour exploiter un agent IA en production. Avec l'exemple de notre agent Helpy.
6/10/2026
Assistant IA symbolisé par un robot au-dessus d'une main devant un ordinateur portable
Cybersecurity

Sécuriser MCP en entreprise : risques et bonnes pratiques pour les DSI

Model Context Protocol (MCP) : les risques de sécurité pour l'entreprise (serveurs non vérifiés, droits trop larges, injections) et les bonnes pratiques.
5/10/2026
IT Systems Consultant showing a monitoring dashboard to a colleague
Cybersecurity

Superviser un agent IA en production : méthode et indicateurs

Superviser un agent IA en production : actions, erreurs, coûts, dérives, seuils de reprise en main et indicateurs. La méthode appliquée à notre agent Helpy.
2/10/2026