📊 HiddenMerit Morning Post · Issue 74
Focus on Database Frontiers, Practical Insights for DBAs August 12, 2026 | 5 Selected Global Breaking News
01|Metabase Exposes CVSS 10.0 Zero‑Day SQL Injection (CVE-2026-72898): Unauthenticated Takeover, Active Exploitation in the Wild
On August 11, Metabase officially disclosed a critical SQL injection vulnerability, assigned CVE-2026-72898, with a CVSS score of 10.0 (the highest risk level), and confirmed active exploitation in the wild.
Vulnerability Details: The vulnerability resides in the unauthenticated POST /api/session/reset_password endpoint. During the password reset flow, Metabase fails to restrict undeclared fields in the request body, allowing attackers to pass unexpected values as structured input to the application database query. Through this vulnerability, a remote unauthenticated attacker can inject arbitrary SQL into the Metabase application database and gain administrative privileges over the instance.
Impact and Fix: Affected versions cover branches 1.58 through 1.63. Patched versions include:
- 1.58.x: Upgrade to 1.58.24 or higher
- 1.59.x: Upgrade to 1.59.21 or higher
- 1.60.x: Upgrade to 1.60.17 or higher
- 1.61.x: Upgrade to 1.61.11 or higher
- 1.62.x: Upgrade to 1.62.9 or higher
- 1.63.x: Upgrade to 1.63.5 or higher
Compromise Indicators: If an access pattern of POST /api/session/reset_password returning 400 followed immediately by GET /api/user/current returning 200 is detected, the instance is highly likely compromised.
- DBA Perspective: CVSS 10.0 means an attacker can fully compromise the target system without any credentials. DBAs of Metabase self‑hosted instances should immediately take three actions: upgrade to the patched version, revoke all active sessions (delete the
core_sessiontable), and rotate all credentials to connected databases. Metabase typically holds high‑privilege database connections – once compromised, it can become a bridge for attackers to enter enterprise internal networks.
02|OceanBase Launches First External Funding Round: Targeting RMB 2‑3 Billion, Annualized Revenue Exceeds RMB 1.4 Billion, Benchmarking “China’s Databricks”
Ant Group’s distributed database company OceanBase officially launched its Series A funding round on July 29, targeting approximately RMB 2‑3 billion, and has already engaged with multiple leading investment institutions. This marks the first time OceanBase has introduced external funding since its establishment.
Key Data: In 2026, OceanBase’s annualized revenue has exceeded RMB 1.4 billion, representing approximately 70% year‑on‑year growth. The company has thousands of customers, primarily including Bank of Communications and China Mobile. According to IDC data, OceanBase ranked first in market share for distributed database on‑premises deployment in China in 2025.
Strategic Benchmarking: Bloomberg has referred to OceanBase as “China’s Databricks.” OceanBase is evolving from a distributed database toward an AI data platform, benchmarking against U.S. data and AI platform company Databricks. The “lakehouse‑integrated” AI database released in June has been tested in dozens of customer scenarios. In 2024, OceanBase established an independent board of directors and an employee equity incentive mechanism.
Multiple Ant Group subsidiaries are pursuing independent financing: Ant International completed a Series A round of approximately $1.2 billion in July, and Ant Digital is preparing for a Pre‑IPO round.
- DBA Perspective: OceanBase’s first external funding is a landmark event for domestic databases moving toward “market‑oriented independent operations.” The annualized revenue exceeding RMB 1.4 billion and 70% growth validate the commercial maturity of domestic distributed databases. Benchmarking against Databricks means OceanBase’s strategic direction is extending from a “distributed database company” to an “AI data platform” – DBA skills need to expand from “distributed database operations” to “AI data platform architecture and multi‑modal data management.”
03|Dameng Receives Another Major Shareholder Increase to 26.96%: Two Increases in One Month, Industrial Capital Continues to “Double Down”
On August 7, Dameng (688692) announced that shareholder CEC Investment Holdings Co., Ltd. increased its shareholding by 2,217,000 shares (representing 1.96% of total share capital) via block trading on August 6. After this increase, the combined shareholding of CEC Investment and its concert party China Software rose from 25.00% to 26.96% , with the equity change reaching a 1% multiple.
This increase was implemented by China Electronics Corporation Group through its wholly‑owned subsidiary CEC Investment, based on “strong confidence in the company’s future sustainable and stable development,” with all funds coming from its own capital. On July 28, CEC Investment had already increased its shareholding by 11,758 shares via block trading, raising its holding from 24.99% to 25.00%. Dameng’s 2025 revenue was RMB 1.306 billion, with net profit of RMB 515 million.
- DBA Perspective: Two increases within a month, with the shareholding approaching 27%, sends a strong signal of continued bullishness from industrial capital toward leading domestic database vendors. The strong endorsement from China Electronics Corporation, a key state‑owned enterprise, provides confidence in ecosystem stability for DBAs selecting Dameng products in Xinchuang projects in finance, government, and other sectors.
04|CVE-2026-72900: Metabase Low‑Privilege Authenticated Users Can Read Entire Application Database
On August 10, Metabase concurrently disclosed CVE-2026-72898 (CVSS 10.0, unauthenticated RCE) and CVE-2026-72900 (CVSS v4 score 7.1, High), the latter allowing low‑privilege authenticated attackers to read the entire Metabase application database.
Vulnerability Details: CVE-2026-72900 allows low‑privilege authenticated users to access the full contents of the Metabase application database. The attack vector is remote network exploitation, with low attack complexity, requiring low‑privilege authenticated user identity, no user interaction, and high impact on confidentiality.
- DBA Perspective: Metabase has disclosed two high‑risk vulnerabilities in a single week – one allowing unauthenticated RCE (CVSS 10.0), and another allowing low‑privilege users to read the full database (CVSS 7.1). Combined, they pose an extremely high risk to Metabase deployments: attackers can first exploit CVE-2026-72898 to gain administrative privileges, then use CVE-2026-72900 to continuously steal database contents. DBAs using Metabase should immediately upgrade versions and review the credentials and permissions of connected databases.
05|CETC Kingware Releases Domestic Database Panorama: Xinchuang Ecosystem Moving from “Replacement” to “Leadership”
In early August, CETC Kingware published a series of technical articles, including “Domestic Database Panorama: A Complete View of Technical Architecture and Ecosystem Landscape” and “Domestic Database Panorama: In‑Depth Analysis of Mainstream Technology Paths and Market Landscape,” systematically outlining the domestic database market landscape and selection frameworks.
Core Judgment: The domestic database industry is presenting a landscape of “four pillars” – traditional vendors, startups, cloud vendors, and cross‑industry vendors. The industry is undergoing a profound transformation from “passive operations” to “active operations,” with heterogeneous database compatibility and distributed architecture elasticity becoming key variables determining system stability. Domestic databases have moved from “usable” to “good‑to‑use” in the deep water zone, with penetration rates accelerating in critical sectors such as finance and healthcare.
Four Vendor Categories:
- Traditional Vendors (CETC Kingware, Dameng, etc.): Deep technical accumulation, extensive industry validation, strong stability in core transaction systems.
- Startups (PingCAP, Guangshen, etc.): Novel technical architectures, focused on distributed and cloud‑native directions.
- Cloud Vendors (Alibaba Cloud, Huawei Cloud, Tencent Cloud, etc.): Leveraging cloud infrastructure, emphasising elastic scaling and cloud‑native integration.
- Cross‑Industry Vendors (ZTE, Neusoft, Inspur, etc.): Software‑hardware integrated products, combining their own hardware/solution advantages.
Technology Trends: Centralised and distributed architectures evolving in parallel. KingbaseES, as an enterprise‑grade large‑scale converged database for critical applications across all industries, is suitable for transaction processing, data analytics, massive time‑series data collection, and other scenarios, with a wealth of successful cases in financial and government core systems.
- DBA Perspective: Kingware’s panorama provides DBAs with a macro‑coordinate system for cross‑industry Xinchuang selection. The four‑vendor landscape means DBAs need to match vendor types based on their industry context – in financial core sectors, prioritise traditional vendors’ stability and depth of industry validation; in internet high‑concurrency scenarios, focus on startups’ distributed innovation. The judgment that the Xinchuang ecosystem is moving from “replacement” to “leadership” also validates the trend of DBA skills evolving from “compatibility assessment” to “deep mastery of self‑developed kernel tuning.”
📚 SQL Little Knowledge Point
This Issue’s Knowledge Point: What is CVSS 10.0?
CVSS 10.0 is the highest risk rating in the Common Vulnerability Scoring System. Metabase CVE-2026-72898 is at this level, meaning the vulnerability satisfies all of the following conditions:
| CVSS Metric | Meaning | CVE-2026-72898 Status |
|---|---|---|
| AV:N | Remotely exploitable over network | Attackable from the public internet |
| AC:L | Low exploitation difficulty, no special conditions | No additional conditions required |
| PR:N | No authentication required | Any attacker can trigger |
| UI:N | No user interaction required | No clicks or actions needed |
| S:C | Scope changed – affects associated systems | Can move laterally into internal networks |
| C:H/I:H/A:H | Complete loss of confidentiality/integrity/availability | Data breach + system control |
CVSS 10.0 means: An attacker can fully compromise the target system with just network access, without any credentials or user interaction. A CVSS 10.0 vulnerability should not be treated as “need to fix soon” but as an emergency security incident that has “already been weaponised.”
HiddenMerit Team Production Slogan: 绩优隐于内,金石启新程 | Hidden deep. Merit bold. Forge ahead.