Metabase unauthenticated SQL injection zero-day actively exploited SQL injection flaw
Vulnerability
Summary
Hide ▲
Show ▼
A Metabase unauthenticated SQL injection zero-day put Metabase Cloud and self-hosted installations at risk of administrator takeover, credential theft, and data export. The flaw affected versions 1.58 and above and was confirmed actively exploited before disclosure on Aug. 7, 2026. Metabase said it blocked the attack endpoints and rolled out a fix for the vulnerability. Organizations running exposed self-hosted installs were told to upgrade immediately or temporarily block `/api/session/reset_password` while applying the patch.
Timeline
-
07.08.2026 23:14 1 articles · 1h ago
Metabase zero-day attacks breach customer instances
Exploitation ObservedAttackers exploited an unauthenticated SQL injection flaw in Metabase versions 1.58 and above during zero-day attacks on August 3, breaching customer instances and compromising Tally's Metabase analytics environment.
Show sources
- Metabase SQLi zero-day exploited in customer data-theft attacks — www.bleepingcomputer.com — 07.08.2026 23:14
-
07.08.2026 23:14 2 articles · 1h ago
Metabase confirms active exploitation and rolls out a fix
Initial DisclosureMetabase disclosed the attacks on Thursday, said Metabase Cloud had been hit through a previously unknown vulnerability affecting versions 1.58 and above, confirmed active exploitation, blocked the endpoints used for the attack, and rolled out a fix; self-hosted customers were told to upgrade immediately or temporarily block '/api/session/reset_password'.
Show sources
- Metabase SQLi zero-day exploited in customer data-theft attacks — www.bleepingcomputer.com — 07.08.2026 23:14
- Metabase SQLi zero-day exploited in customer data-theft attacks — www.bleepingcomputer.com — 07.08.2026 23:14