Metabase SQLi zero-day exploited in customer data-theft attacks

Critical Metabase SQL Injection Vulnerability Exposed in Customer Data-Theft Attacks

A devastating zero-day attack on Metabase, a popular business intelligence and analytics platform, has compromised customer instances across multiple high-profile companies. The unauthenticated SQL injection vulnerability, affecting versions 1.58 and above, allowed attackers to inject arbitrary code into the application database, granting them administrator access and enabling data theft.

Metabase Cloud SaaS customers are most affected, but self-hosted installations of the platform are also vulnerable. In a security advisory, Metabase warned that the flaw is “CRITICAL” with a CVSS score of 10.0, making it one of the most severe vulnerabilities discovered this year. The company confirmed that the vulnerability has been actively exploited in attacks targeting customer instances.

The SQL injection attack works by allowing an unauthorized user to inject malicious code into the Metabase application database. This can grant the attacker administrator access to the instance, enabling them to change configuration settings, steal stored credentials for connected databases, read any data accessible through those connections, and export sensitive information. In a worst-case scenario, attackers could use this vulnerability to gain full control over the affected instance.

Metabase has taken swift action to mitigate the damage by blocking the endpoints used in the attack and releasing patches for all affected versions. The company advises its Cloud customers that they have already been upgraded and patched, while self-hosted installations must manually update to a secure version. Organizations unable to apply the patch immediately are advised to temporarily block access to the ‘/api/session/reset_password’ endpoint.

Several prominent companies have confirmed that their customer data was compromised in the attack. Laptop maker Framework revealed that attackers stole customer information, including full names, email addresses, and billing address details. Online form builder Tally also notified its users that its Metabase analytics environment was compromised on August 3, potentially exposing email addresses and passwords stored as cryptographic hashes.

While LexisNexis has warned its customers about a cyberattack at one of its third-party vendors, it is unclear whether the Metabase vulnerability was involved. However, it is clear that multiple companies have fallen victim to the same zero-day attack, highlighting the critical need for timely patching and vigilant monitoring of system logs.

To protect against similar attacks in the future, we recommend that organizations running self-hosted Metabase installations take immediate action by updating their platform to a secure version. Additionally, they should:

* Revoke all active user sessions

* Review API keys and administrator accounts for unauthorized changes

* Rotate credentials for connected databases

* Inspect logs and query history for signs of compromise

By taking these proactive steps, organizations can minimize the risk of falling victim to similar data-theft attacks in the future.


Source: Bleeping Computer — 2026-08-07