Metabase unauthenticated SQL injection zero-day actively exploited SQL injection flaw
Vulnerability
Summary
Hide ▲
Show ▼
A Metabase unauthenticated SQL injection zero-day put Metabase Cloud and self-hosted installations at risk of administrator takeover, credential theft, and data export. The flaw affected versions 1.58 and above and was confirmed actively exploited before disclosure on Aug. 7, 2026. Metabase said it blocked the attack endpoints and rolled out a fix for the vulnerability. Organizations running exposed self-hosted installs were told to upgrade immediately or temporarily block `/api/session/reset_password` while applying the patch.
Timeline
-
08.08.2026 09:58 1 articles · 13d ago
Framework customer data was accessed in Metabase zero-day compromise
Victim Impact UpdateFramework said customer names, login IPs, addresses, phone numbers, and emails were accessed during the Metabase zero-day compromise, while order and payment information were not accessed.
Show sources
- Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication — thehackernews.com — 08.08.2026 09:58
-
07.08.2026 23:14 1 articles · 13d ago
Metabase zero-day attacks breach customer instances
Exploitation ObservedAttackers exploited an unauthenticated SQL injection flaw in Metabase versions 1.58 and above during zero-day attacks on August 3, breaching customer instances and compromising Tally's Metabase analytics environment.
Show sources
- Metabase SQLi zero-day exploited in customer data-theft attacks — www.bleepingcomputer.com — 07.08.2026 23:14
-
07.08.2026 23:14 2 articles · 13d ago
Metabase confirms active exploitation and rolls out a fix
Initial DisclosureMetabase disclosed the attacks on Thursday, said Metabase Cloud had been hit through a previously unknown vulnerability affecting versions 1.58 and above, confirmed active exploitation, blocked the endpoints used for the attack, and rolled out a fix; self-hosted customers were told to upgrade immediately or temporarily block '/api/session/reset_password'.
Show sources
- Metabase SQLi zero-day exploited in customer data-theft attacks — www.bleepingcomputer.com — 07.08.2026 23:14
- Metabase SQLi zero-day exploited in customer data-theft attacks — www.bleepingcomputer.com — 07.08.2026 23:14