Metabase says an actively exploited SQL injection zero-day let attackers steal data from customer instances

Metabase says attackers used a previously unknown flaw in its analytics platform to break into customer instances and steal data, including confirmed impacts at Framework and Tally. The bug is an unauthenticated SQL injection vulnerability with a CVSS score of 10.0 affecting Metabase versions 1.58 and above, including Metabase Cloud and self-hosted deployments. Metabase says patched releases include 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, and 0.63.5, and recommends blocking /api/session/reset_password if immediate upgrading is not possible.
Why it matters: Organizations using Metabase may have had attacker access to dashboards, connected database credentials, and underlying customer data without needing a login. This is urgent: update immediately, revoke sessions, review admin changes and API keys, and rotate credentials for connected databases.

Sources

Framework loses customer data in Metabase zero-day attack
2026.08.10 95% relevant
This report identifies Framework as a confirmed victim of the Metabase zero-day, says all customers were affected, lists exposed data fields, and adds timeline and response details including Metabase's August 3 discovery and August 6 notification.
Metabase Patches Vulnerability Exploited as Zero-Day
Ionut Arghire 2026.08.10 98% relevant
This source is a direct update on the same event, adding Metabase's patch availability, affected fixed versions (63.5, 62.9, 61.11, 60.17, 59.21, 58.24), temporary mitigation by blocking /api/session/reset_password, and concrete indicators of compromise tied to the Metabase Cloud attack.
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
info@thehackernews.com (The Hacker News) 2026.08.08 95% relevant
This is the same underlying event: the actively exploited Metabase zero-day. This source adds that the flaw can grant unauthenticated administrator access, sharpening the immediate impact and urgency for Metabase users.
Metabase SQLi zero-day exploited in customer data-theft attacks
Mayank Parmar 2026.08.07 100% relevant
This article establishes a new tracked incident by tying an actively exploited Metabase zero-day to confirmed customer data theft at named victims and providing concrete affected versions, mitigations, and signs of compromise.
← Back to all stories