Executive Summary
Netwrix Access Analyzer 26 incorporates a version of Metabase, a third-party business intelligence and analytics platform, affected by three recently disclosed vulnerabilities. These issues could allow an unauthenticated, network-based attacker to compromise the confidentiality, integrity, and availability of the affected system.
While Netwrix is unaware of any current exploitation of these vulnerabilities, all Netwrix Access Analyzer 26 customers are advised to apply the available update immediately.
Vulnerability
| Title | Affected Component | Affected Versions | CVSS 4.0 Score | CVSS 3.1 Score (Base / Temporal) | Description |
|---|---|---|---|---|---|
| Dependency on Vulnerable Third-Party Components (CVE-2026-72898, CVE-2026-72899, CVE-2026-72900) | Netwrix Access Analyzer 26 | < 1.1.1 | 9.3 | 9.8 / 8.5 | Netwrix Access Analyzer 26 incorporates a version of Metabase affected by three recently disclosed vulnerabilities. |
Exploitability
Factors such as whether details about the vulnerability are publicly known, whether an exploit is readily available, or whether adversaries are actively exploiting the vulnerability are valuable in making risk-based judgments about urgency and priority; customers should use the information below in making those decisions.
| Title | Publicly known? | Exploit available? | Actively exploited? |
|---|---|---|---|
| Dependency on Vulnerable Third-Party Components (CVE-2026-72898, CVE-2026-72899, CVE-2026-72900) | No | No | No |
Solution
Netwrix Access Analyzer 26 automatically updates to the remediated version as soon as it becomes available. If automatic updates have been disabled, please follow the instructions at Upgrade to a New Version.
To confirm the fix has been applied, run dspmctl version and verify the reported version is 1.1.1 or later. Additional information can be found in the Netwrix Access Analyzer documentation.
Please contact the Netwrix technical support team should you need assistance.
Official Fixes
Updated software has been released containing official fixes for all listed vulnerabilities as indicated in the table below.
| Product | Release Version |
|---|---|
| Netwrix Access Analyzer 26 | 1.1.1 |
FAQ
-
How do I confirm that the fix has been applied?
Run
dspmctl versionfrom the command line. If the reported version is 1.1.1 or later, the fix has been successfully applied. -
Are there any configuration changes required after updating?
No additional configuration changes are required. The fix is automatically applied upon updating to the remediated version.
Revisions
Updates to this advisory may be made as necessary. Information about each change will be published in the table below.
| Revision | Date | Description |
|---|---|---|
| 1 | 2026-09-18T12:00:00Z | First published |
| 2 | 2026-09-18T15:00:00Z | Clarifying impacted version is Access Analyzer 26 |
Disclaimer
The information and materials included in or linked to this Security Advisory are provided on an “as-is” basis and without warranty of any kind, and we disclaim all representations and warranties of any kind, whether express or implied, including warranties of merchantability and fitness for a particular use. You acknowledge and agree that your use of the information and materials included in or linked to this Security Advisory are at your own risk.