Find notable cyber news and cases, enriched with sources, timelines, and signals.

Metabase unauthenticated SQL injection zero-day actively exploited SQL injection flaw

Vulnerability
First reported
Last updated
Happening score
H score 52
1 unique sources, 1 articles

Summary

Hide ▲

A Metabase unauthenticated SQL injection zero-day put Metabase Cloud and self-hosted installations at risk of administrator takeover, credential theft, and data export. The flaw affected versions 1.58 and above and was confirmed actively exploited before disclosure on Aug. 7, 2026. Metabase said it blocked the attack endpoints and rolled out a fix for the vulnerability. Organizations running exposed self-hosted installs were told to upgrade immediately or temporarily block `/api/session/reset_password` while applying the patch.

Timeline

  1. 07.08.2026 23:14 1 articles · 1h ago

    Metabase zero-day attacks breach customer instances

    Exploitation Observed

    Attackers exploited an unauthenticated SQL injection flaw in Metabase versions 1.58 and above during zero-day attacks on August 3, breaching customer instances and compromising Tally's Metabase analytics environment.

    Show sources
  2. 07.08.2026 23:14 2 articles · 1h ago

    Metabase confirms active exploitation and rolls out a fix

    Initial Disclosure

    Metabase disclosed the attacks on Thursday, said Metabase Cloud had been hit through a previously unknown vulnerability affecting versions 1.58 and above, confirmed active exploitation, blocked the endpoints used for the attack, and rolled out a fix; self-hosted customers were told to upgrade immediately or temporarily block '/api/session/reset_password'.

    Show sources