A critical SQL injection vulnerability in Metabase has already been exploited in zero-day attacks, aimed at accessing customer premises and extracting data. The Metabase zero-day affects both the Cloud service and on-premises installations hosted by organizations.
BleepingComputer Metabase disclosed the attack on August 6. The company describes a previously unknown bug in versions 1.58 and later, and the advisory on GitHub classifies it as critical, with a CVSS score of 10.0. It has not yet been assigned a CVE identifier.
See also: khunt: SQL Injection in Oracle leads to SYSTEM access
How Metabase zero-day works
The issue is an unauthorized SQL injection that allows a remote attacker to enter arbitrary commands into the application's database without having an account. The chain can lead to administrator privileges within the installation and, from there, to changes to settings or accounts.
With administrator access, an attacker can look up stored credentials for connected databases, read information available through those connections, and extract data. Metabase confirms that the Metabase zero-day is actively exploited, so the mere absence of evidence of a breach is not enough to consider an installation secure.
The vulnerability affects branches 0.58 to 0.63. The minimum safe versions are 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, and 0.63.5, respectively. Metabase Cloud customers have already been upgraded by the company, but organizations with self-managed installations must manually perform the update.

Attack indications and affected services
For temporary protection until the upgrade is complete, Metabase recommends blocking the /api/session/reset_password. Administrators can look in the logs for a POST to this path that returns a 400 code followed by a successful GET to /api/user/current. The presence of this pattern should be treated as a potential breach.
Framework informed customers that its installation was accessed on August 3 and that Metabase notified it on August 6. According to the update, names, email addresses, billing and shipping addresses, phone numbers, company details and connection IP addresses were exposed. Tally also announced that its analytics environment was breached on August 3, exposing email addresses and hashed passwords, but not form entries or responses.
LexisNexis reported unusual activity on third-party servers and took services including the Metabase API offline. It is unclear whether customer data was compromised, as the company continues to investigate with an external digital forensics team.
See also: cPanel: Critical SQL vulnerability allows execution as root
What should administrators do?
Metabase management teams should immediately upgrade to the patched version of the relevant branch and revoke all active user connections. In addition, administrator accounts and API keys should be checked for unauthorized changes, and credentials of connected databases should be rotated.

Investigation should not be limited to the point of entry. It is recommended to check logs, query history, and exports for unusual activity. The Metabase zero-day shows that an analytics platform can act as a gateway to many connected data sources, so immediate updates and changing secrets should be done in conjunction.
See also: CVE-2026-63030: critical WordPress vulnerability actively exploited

Metabase has blocked the points used in the attack and has released fixes, but self-managed installations remain the responsibility of organizations. The SecNews technical team recommends that any affected version be considered potentially compromised until upgrades, audits, and credential rotation are complete.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
