Metabase Zero-Day SQL Injection Exploited to Steal Data from Customer Instances

Critical zero-day SQL injection in Metabase allows data theft from cloud and self-hosted instances. Updates and mitigation steps provided.

Metabase Zero-Day SQL Injection Exploited to Steal Data from Customer Instances
Vulnerabilities

Illustrative image generated with AI

Active Attacks Targeting Metabase Cloud and Self-Hosted Deployments

Metabase confirmed on August 7, 2026, an ongoing zero-day attack campaign targeting Metabase Cloud, caused by a vulnerability affecting versions 1.58 and later.

The flaw is a critical unauthenticated SQL injection vulnerability with a CVSS score of 10.0. A remote attacker can inject arbitrary SQL commands into the application database without an account and gain administrative privileges on the instance.

This access may allow an attacker to:

  • modify the configuration;
  • steal credentials for connected databases;
  • access data available through those connections;
  • export information from the compromised environment.

The attacker has not been identified. The vulnerability does not currently have a CVE identifier.

Metabase has blocked the endpoints used in the attacks and fixed the cloud service. Self-hosted deployments, however, require a manual update.

Vulnerable Versions and Available Fixes

Fixes have been released for branches 0.58 through 0.63. The minimum secure versions are:

  • 0.58.24
  • 0.59.21
  • 0.60.17
  • 0.61.11
  • 0.62.9
  • 0.63.5

Administrators should immediately update self-hosted instances to the fixed version for their respective branch. If an immediate update is not possible, Metabase recommends temporarily blocking access to:

/api/session/reset_password

This mitigation does not replace applying the patch.

Stolen Data and Affected Organizations

Framework confirmed that data was stolen after its Metabase instance was compromised. The access occurred on August 3, 2026, and the company was notified on August 6, 2026.

Potentially stolen information includes full names, email addresses, login IP addresses, billing and shipping addresses, phone numbers, and company names. For Framework for Business customers, the affected data also includes company names, phone numbers, VAT numbers, EINs, and billing email addresses.

Tally reported that its Metabase analytics environment was compromised on August 3, 2026. The incident involved email addresses and cryptographic password hashes. Submitted forms and responses were stored separately and do not appear to have been affected. It is not known which hashing algorithm was used or whether the hashes were protected with a salt.

LexisNexis reported an attack at a third-party provider that affected the Diligence, Metabase API, and Newsdesk services. The company detected anomalous activity on the provider’s servers and disconnected the affected systems. However, it did not explicitly state that the incident was connected to the Metabase API.

How to Check for a Possible Compromise

A potentially indicative sequence in the logs includes:

  1. a POST request to /api/session/reset_password returning HTTP 400;
  2. a subsequent GET request to /api/user/current.

The presence of both requests in system logs may indicate a compromise. Administrators should also:

  • revoke all active user sessions;
  • review API keys and administrative accounts;
  • rotate credentials for connected databases;
  • analyze logs and query history;
  • look for unauthorized configuration changes or unusual data exports.

Because the flaw has been actively exploited, log review should also be performed after the fix has been installed.

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →