Metabase Patches Critical SQL Injection Vulnerability Exploited in Wild
A critical-severity SQL injection vulnerability in Metabase’s data analytics solutions has been exploited by attackers as a zero-day, allowing them to gain administrative access and steal sensitive data. The company has released urgent patches for the flaw, which affects multiple versions of its software.
The vulnerability allows remote, unauthenticated attackers to inject arbitrary SQL queries into the Metabase application database, enabling them to manipulate configuration settings, extract stored credentials for connected databases, and export sensitive data. Metabase warns that an attacker could use this access to change the application’s configuration, steal user credentials, or even read any data accessible through the connected databases.
The vulnerability was discovered after a threat actor exploited it in an attack targeting Metabase Cloud, which has already been patched. However, self-hosting users are advised to apply the patches as soon as possible to prevent exposure. If patching is not possible, users can block the /api/session/reset_password endpoint as a temporary workaround.
To identify potential compromises, users should monitor their application logs and server ingress logs for specific patterns, including POST requests to the reset password endpoint followed by GET requests to the current user endpoint. If this pattern appears in the logs, it is likely that the instance has been compromised.
Metabase recommends several steps for affected users, including revoking all active user sessions, reviewing API keys and deleting any unrecognized keys, rotating credentials for connected databases, and reviewing logs and activity for suspicious access. Users should also review administrative accounts and rotate their credentials to prevent unauthorized access.
The vulnerability affects multiple versions of Metabase’s software, including 63.5, 62.9, 61.11, 60.17, 59.21, and 58.24. Users are advised to update their software as soon as possible to prevent exploitation.
In a statement, Metabase emphasized the urgency of patching the vulnerability, warning that attackers could use this flaw to gain administrative access and steal sensitive data. The company’s rapid response to the incident highlights the importance of regular security updates and monitoring for vulnerabilities in critical systems.
As cybersecurity threats continue to evolve, it is essential for users to stay informed about potential vulnerabilities and take proactive measures to protect their systems. Metabase’s prompt action demonstrates that timely patching can mitigate the impact of such attacks. Users should prioritize applying the patches for this vulnerability as soon as possible to ensure the integrity of their data analytics solutions.
By taking these steps, users can minimize the risk of exploitation and maintain the security of their Metabase installations.
Source: SecurityWeek — 2026-08-10